CVE-2026-83497 - OpenSearch SQ... Note

CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination

An important security bulletin has been issued for OpenSearch, specifically addressing CVE-2026-83497. This vulnerability allows a remote authenticated user with minimal permissions to execute arbitrary code by exploiting the plugins/sql endpoint with a malicious cursor parameter. The issue affects self-managed OpenSearch SQL Plugin versions 2.8 through 3.6, with fixes available in versions 3.7 and 2.19.6. Amazon OpenSearch Service versions 2.9 through 3.5 are also affected but have been patched through service software updates.