CVE-2026-83497: Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote authenticated user with basic read or search permissions can exploit it. Exploitation is performed through the plugins/sql endpoint using a crafted cursor parameter.
What is the potential impact of successful exploitation?
Successful exploitation can allow arbitrary code execution on the server. The stated impact includes high confidentiality, integrity, and availability consequences.
Which releases should be reviewed for remediation information?
The provided references include OpenSearch release artifacts for versions 3.7.0 and 2.19.6, as well as an AWS security bulletin. Confirm remediation applicability against those sources for your deployment.