AWS Latest Bulletins
Follow
CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
An important security bulletin has been issued for OpenSearch, specifically addressing CVE-2026-83497. This vulnerability allows a remote authenticated user with minimal permissions to execute arbitrary code by exploiting the plugins/sql endpoint with a malicious cursor parameter. The issue affects self-managed OpenSearch SQL Plugin versions 2.8 through 3.6, with fixes available in versions 3.7 and 2.19.6. Amazon OpenSearch Service versions 2.9 through 3.5 are also affected but have been patched through service software updates.