logo

Critical 9.3 CVSS RCE Vulnerability Hit in OpenTelemetry Java Agent

ID: 426ac828-543d-5632-b7f9-f0315025bac9

STIX ID: report--426ac828-543d-5632-b7f9-f0315025bac9

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical RCE vulnerability (CVE-2026-33701, CVSS 9.3) was found in OpenTelemetry Java instrumentation: its RMI monitoring endpoint deserializes network data without proper filters, allowing an attacker with network access to a JMX/RMI port and the right gadget chain on the classpath to execute arbitrary code. Users should immediately upgrade to version 2.26.1 or, as a temporary mitigation, start the JVM with -Dotel.instrumentation.rmi.enabled=false to disable the RMI instrumentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.