OpenSearch SQL Cursor Pagination Unrestricted Deserialization RCE
CVE-2026-83497 Published on August 31, 2026
Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
Vulnerability Analysis
CVE-2026-83497 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a Marshaling, Unmarshaling Vulnerability?
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVE-2026-83497 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.
Products Associated with CVE-2026-83497
stack.watch emails you whenever new vulnerabilities are published in Opensearch or Amazon Opensearch Service. Just hit a watch button to start following.
Affected Versions
OpenSearch:- Version 2.8, <= 3.6 is affected.
- Version 2.9, <= 3.5 is affected.