Critical 9.3 CVSS RCE Vulnerability Hit in OpenTelemetry Java Agent
ID: 426ac828-543d-5632-b7f9-f0315025bac9
STIX ID: report--426ac828-543d-5632-b7f9-f0315025bac9
Feed Name: securityonline.info
A critical RCE vulnerability (CVE-2026-33701, CVSS 9.3) was found in OpenTelemetry Java instrumentation: its RMI monitoring endpoint deserializes network data without proper filters, allowing an attacker with network access to a JMX/RMI port and the right gadget chain on the classpath to execute arbitrary code. Users should immediately upgrade to version 2.26.1 or, as a temporary mitigation, start the JVM with -Dotel.instrumentation.rmi.enabled=false to disable the RMI instrumentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
