CVE-2026-83497

Summary

Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.

Affected Software

VendorProductVersion RangeStatus
OpenSearchOpenSearch2.8 <= 3.6affected
AmazonAmazon OpenSearch Service2.9 <= 3.5affected

Weaknesses

  • CWE-502: CWE-502 Deserialization of untrusted data

References