CVE-2026-83497
HIGH
NVD
CVSS Score
8.8
Severity
HIGH
Published
Aug 31, 2026
Vendor
unknown
Description
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.