<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Amazon OpenSearch Service on Cloudkaramchari</title><link>https://www.cloudkaramchari.com/tags/amazon-opensearch-service/</link><description>Recent content in Amazon OpenSearch Service on Cloudkaramchari</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>cloudkaramchari</copyright><lastBuildDate>Tue, 22 Sep 2026 10:00:00 +0530</lastBuildDate><atom:link href="https://www.cloudkaramchari.com/tags/amazon-opensearch-service/index.xml" rel="self" type="application/rss+xml"/><item><title>Fix CVE-2026-83497: OpenSearch SQL Plugin Deserialization RCE via Cursor Pagination</title><link>https://www.cloudkaramchari.com/blog/fix-cve-2026-83497-opensearch-sql-plugin-deserialization-rce/</link><pubDate>Tue, 22 Sep 2026 10:00:00 +0530</pubDate><guid>https://www.cloudkaramchari.com/blog/fix-cve-2026-83497-opensearch-sql-plugin-deserialization-rce/</guid><description>
&lt;h1 id="fix-cve-2026-83497-opensearch-sql-plugin-deserialization-rce-via-cursor-pagination">Fix CVE-2026-83497: OpenSearch SQL Plugin Deserialization RCE via Cursor Pagination&lt;/h1>
&lt;p>If you run OpenSearch — self-managed or Amazon OpenSearch Service — and have the SQL plugin enabled, a user with nothing more than basic read/search rights can get arbitrary code execution on your cluster right now. CVE-2026-83497, published August 31, 2026, is an unrestricted Java deserialization bug in the SQL plugin's cursor pagination feature. It carries a CVSS 3.1 base score of 8.8 (&lt;code>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H&lt;/code>) — network-exploitable, low complexity, no user interaction, and full confidentiality/integrity/availability impact once triggered.&lt;/p></description></item></channel></rss>