SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-83497

HIGH · CVSS 8.8 EPSS 0.52%

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The OpenSearch SQL plugin is vulnerable to unrestricted deserialization of untrusted data, allowing remote authenticated users with basic read/search permissions to execute arbitrary code on the server by manipulating the cursor parameter. This high-severity flaw poses a significant risk to server integrity and data security. Organizations using the OpenSearch SQL plugin should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-83497
Severity
HIGH
CVSS
8.8
EPSS
0.52%

Original NVD Description

Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.