In plain language
What this advisory means
A security flaw in the OpenSearch SQL Plugin lets someone with basic read or search permissions run harmful code on the server remotely. This happens when they send a specially crafted input to the plugin. AWS has released updates to fix this issue and recommends users upgrade their software or service immediately.
Technical explanation
How the issue affects the environment
CVE-2026-83497 is a vulnerability in OpenSearch SQL Plugin versions 2.8 to 3.6 involving unrestricted Java deserialization in the cursor pagination functionality. An authenticated attacker with basic read/search privileges can exploit this by supplying a malicious serialized object in the cursor parameter of the plugins/sql endpoint. The vulnerability allows arbitrary code execution on the server. AWS fixed this by updating OpenSearch SQL Plugin to versions 2.19.6 and 3.7. Managed Amazon OpenSearch Service domains running versions 2.9 to 3.5 receive patches via service software updates without needing an engine upgrade.
Operational impact
Why teams should care
Exploitation lets an authenticated user remotely execute arbitrary code on the server hosting OpenSearch SQL Plugin. This can lead to full server compromise, data breaches, and disruption of search and analytics capabilities, harming business operations and increasing security risks.
Immediate action
For self-managed OpenSearch SQL Plugin, upgrade to version 2.19.6 or 3.7 or later. For Amazon OpenSearch Service users, apply the latest service software update via the AWS Management Console or rely on automatic updates if enabled. Performing these updates ensures patches are applied to mitigate CVE-2026-83497.
Affected and fixed releases
Temporary risk reduction
None provided in the official sources. Immediate software or service update is recommended.
Evidence and validation checklist
- AWS Security Bulletin ID 2026-092-AWS published on 08/31/2026
- Description of vulnerability as unrestricted Java deserialization via crafted cursor parameter
- Affected versions clearly identified for open-source and managed products
- Remediation details specifying fixed versions and update procedures
- No workaround options provided, recommending updates as sole mitigation
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
