Security Advisory Desk
unratedQCS priority 76/100Amazon Web Services

CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination

A security flaw in the OpenSearch SQL Plugin lets someone with basic read or search permissions run harmful code on the server remotely. This happens when they send a specially crafted input to the plugin. AWS has released updates to fix this issue and recommends users upgrade their software or service immediately.

Published 31/8/2026, 6:41:11 pmVerified 31/8/2026, 8:48:36 pmRevision 1
Amazon Web Services unrated network security advisory visual

In plain language

What this advisory means

A security flaw in the OpenSearch SQL Plugin lets someone with basic read or search permissions run harmful code on the server remotely. This happens when they send a specially crafted input to the plugin. AWS has released updates to fix this issue and recommends users upgrade their software or service immediately.

Technical explanation

How the issue affects the environment

CVE-2026-83497 is a vulnerability in OpenSearch SQL Plugin versions 2.8 to 3.6 involving unrestricted Java deserialization in the cursor pagination functionality. An authenticated attacker with basic read/search privileges can exploit this by supplying a malicious serialized object in the cursor parameter of the plugins/sql endpoint. The vulnerability allows arbitrary code execution on the server. AWS fixed this by updating OpenSearch SQL Plugin to versions 2.19.6 and 3.7. Managed Amazon OpenSearch Service domains running versions 2.9 to 3.5 receive patches via service software updates without needing an engine upgrade.

Operational impact

Why teams should care

Exploitation lets an authenticated user remotely execute arbitrary code on the server hosting OpenSearch SQL Plugin. This can lead to full server compromise, data breaches, and disruption of search and analytics capabilities, harming business operations and increasing security risks.

Immediate action

For self-managed OpenSearch SQL Plugin, upgrade to version 2.19.6 or 3.7 or later. For Amazon OpenSearch Service users, apply the latest service software update via the AWS Management Console or rely on automatic updates if enabled. Performing these updates ensures patches are applied to mitigate CVE-2026-83497.

Affected and fixed releases

Affected versionsOpenSearch SQL Plugin v2.8 to v3.6, Amazon OpenSearch Service v2.9 to v3.5
Fixed versionsOpenSearch SQL Plugin v2.19.6 and v3.7, Amazon OpenSearch Service v2.9 to v3.5 (via service software update)

Temporary risk reduction

None provided in the official sources. Immediate software or service update is recommended.

Evidence and validation checklist

  • AWS Security Bulletin ID 2026-092-AWS published on 08/31/2026
  • Description of vulnerability as unrestricted Java deserialization via crafted cursor parameter
  • Affected versions clearly identified for open-source and managed products
  • Remediation details specifying fixed versions and update procedures
  • No workaround options provided, recommending updates as sole mitigation

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source