Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aws
Aws amazon Opensearch Service |
|
| Vendors & Products |
Aws
Aws amazon Opensearch Service |
Mon, 31 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint. | |
| Title | Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination | |
| First Time appeared |
Amazon
Amazon amazon Opensearch Service Opensearch Opensearch opensearch |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:amazon:amazon_opensearch_service:*:*:*:*:*:*:*:* cpe:2.3:a:opensearch:opensearch:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Amazon
Amazon amazon Opensearch Service Opensearch Opensearch opensearch |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-01T14:03:26.045Z
Reserved: 2026-08-31T15:56:44.003Z
Link: CVE-2026-83497
Updated: 2026-09-01T14:03:09.359Z
Status : Received
Published: 2026-08-31T19:17:24.327
Modified: 2026-09-01T15:17:37.857
Link: CVE-2026-83497
No data.
OpenCVE Enrichment
Updated: 2026-08-31T21:00:05Z