CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
Amazon OpenSearch ยท 2026-09-09
Actions
Technical Details
| Affected Versions | v2.8 to v3.6 (open-source), v2.9 to v3.5 (managed) |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-83497 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update OpenSearch SQL Plugin to versions 2.19.6 or 3.7 for open-source deployments and apply the latest service software update for Amazon OpenSearch Service to address the security vulnerability CVE-2026-83497.
For Platform Teams
Deploy the latest OpenSearch SQL Plugin versions and service software updates to ensure the platform remains secure and compliant with best practices, reducing the risk of exploitation.
For Executives
Implement immediate updates to mitigate the risk of remote code execution in OpenSearch SQL Plugin, ensuring system integrity and protecting sensitive data from potential breaches.
Source
Related Amazon OpenSearch Updates
- CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route (2026-09-09)
- CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass (2026-09-09)
- CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin (2026-09-09)
- CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin (2026-09-09)
- Amazon OpenSearch Service adds new Cluster Insights for faster diagnosis of cluster status (2026-08-31)