CVE-2026-83497
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenSearch | OpenSearch | 2.8 <= 3.6 | affected |
| Amazon | Amazon OpenSearch Service | 2.9 <= 3.5 | affected |
Weaknesses
- CWE-502: CWE-502 Deserialization of untrusted data
References
- https://opensearch.org/artifacts/by-version/#release-3-7-0
- https://opensearch.org/artifacts/by-version/#release-2-19-6
- https://aws.amazon.com/security/security-bulletins/2026-092-aws/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.