OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
UnratedCVE-2026-83497 · Published Aug 31, 2026 · updated Sep 9, 2026
Bulletin ID: 2026-092-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/31/2026 11:30 AM PDT Description: OpenSearch is an open-source search and analytics engine. We identified CVE-2026-83497 where a remote authenticated user with basic read/search permissions can run arbitrary code on the server by providing a crafted cursor parameter to the plugins/sql endpoint. Affected Products & Versions: OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.8 to v3.6 - Fixed: versions 3.7 and 2.19.6 Amazon OpenSearch Service (AWS Managed): - Affected: v2.9 to v3.5 - Fixed: v2.9 to v3.5 (via service software update) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 3 | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development... | Unrated | No fix yet |
| Sep 3 | OS command injection in the Amazon CodeCatalyst blueprints SDK | Unrated | No fix yet |
| Sep 2 | Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 | Unrated | No fix yet |
| Sep 1 | Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK | Unrated | No fix yet |
| Aug 28 | Path traversal in the aws:downloadContent plugin in amazon-ssm-agent | Unrated | No fix yet |
| Aug 27 | Zip Slip path traversal in awsdac (diagram-as-code) | Unrated | No fix yet |