OpenSearch SQL Cursor Pagination Unrestricted Deserialization RCE
CVE-2026-83497 Published on August 31, 2026
Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
Vulnerability Analysis
CVE-2026-83497 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is a Marshaling, Unmarshaling Vulnerability?
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
CVE-2026-83497 has been classified to as a Marshaling, Unmarshaling vulnerability or weakness.
Products Associated with CVE-2026-83497
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-83497 are published in these products:
Affected Versions
OpenSearch:- Version 2.8, <= 3.6 is affected.
- Version 2.9, <= 3.5 is affected.