CVE-2026-33701: CWE-502: Deserialization of Untrusted Data in open-telemetry opentelemetry-java-instrumentation
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, OpenTelemetry Java instrumentation is attached as a Java agent (`-javaagent`) on Java 16 or earlier. Second, JMX/RMI port has been explicitly configured via `-Dcom.sun.management.jmxremote.port` and is network-reachable. Third, gadget-chain-compatible library is present on the classpath. This results in arbitrary remote code execution with the privileges of the user running the instrumented JVM. For JDK >= 17, no action is required, but upgrading is strongly encouraged. For JDK < 17, upgrade to version 2.26.1 or later. As a workaround, set the system property `-Dotel.instrumentation.rmi.enabled=false` to disable the RMI integration.
AI Analysis
Technical Summary
OpenTelemetry Java Instrumentation prior to version 2.26.1 registers a custom RMI endpoint that deserializes incoming data without applying serialization filters, leading to a CWE-502 deserialization of untrusted data vulnerability. On JVMs running JDK 16 or earlier, an attacker with network access to a configured JMX or RMI port can exploit this flaw to achieve remote code execution if a gadget-chain-compatible library is present on the classpath. Exploitation requires three conditions: the Java agent is attached, the JMX/RMI port is network-reachable, and the gadget chain is available. The vulnerability allows arbitrary code execution with the privileges of the JVM process. JDK 17 and later are not affected. The vendor recommends upgrading to version 2.26.1 or later or disabling the RMI instrumentation integration as a workaround. Red Hat's advisory confirms the vulnerability and notes that no complete mitigation meeting their criteria is currently available beyond upgrading or disabling the feature.
Potential Impact
An attacker with network access to a configured JMX or RMI port on an instrumented JVM running JDK 16 or earlier can execute arbitrary code remotely with the privileges of the JVM process. This can lead to full compromise of the affected system. The vulnerability requires no user interaction or privileges and has a network attack vector, making it critical in severity. JDK 17 and later are not vulnerable.
Mitigation Recommendations
Upgrade OpenTelemetry Java Instrumentation to version 2.26.1 or later. If upgrading is not immediately possible and the JVM runs JDK 16 or earlier, disable the RMI instrumentation by setting the system property '-Dotel.instrumentation.rmi.enabled=false'. For JDK 17 and later, no action is required but upgrading is recommended. Red Hat notes that no other mitigations meeting their criteria are currently available.
CVE-2026-33701: CWE-502: Deserialization of Untrusted Data in open-telemetry opentelemetry-java-instrumentation
Description
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, OpenTelemetry Java instrumentation is attached as a Java agent (`-javaagent`) on Java 16 or earlier. Second, JMX/RMI port has been explicitly configured via `-Dcom.sun.management.jmxremote.port` and is network-reachable. Third, gadget-chain-compatible library is present on the classpath. This results in arbitrary remote code execution with the privileges of the user running the instrumented JVM. For JDK >= 17, no action is required, but upgrading is strongly encouraged. For JDK < 17, upgrade to version 2.26.1 or later. As a workaround, set the system property `-Dotel.instrumentation.rmi.enabled=false` to disable the RMI integration.
CVSS v4.0
Score 9.3critical
Affected software
open-telemetry
opentelemetry-java-instrumentation
pkg:maven/io.opentelemetry/opentelemetry-java-instrumentationRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenTelemetry Java Instrumentation prior to version 2.26.1 registers a custom RMI endpoint that deserializes incoming data without applying serialization filters, leading to a CWE-502 deserialization of untrusted data vulnerability. On JVMs running JDK 16 or earlier, an attacker with network access to a configured JMX or RMI port can exploit this flaw to achieve remote code execution if a gadget-chain-compatible library is present on the classpath. Exploitation requires three conditions: the Java agent is attached, the JMX/RMI port is network-reachable, and the gadget chain is available. The vulnerability allows arbitrary code execution with the privileges of the JVM process. JDK 17 and later are not affected. The vendor recommends upgrading to version 2.26.1 or later or disabling the RMI instrumentation integration as a workaround. Red Hat's advisory confirms the vulnerability and notes that no complete mitigation meeting their criteria is currently available beyond upgrading or disabling the feature.
Potential Impact
An attacker with network access to a configured JMX or RMI port on an instrumented JVM running JDK 16 or earlier can execute arbitrary code remotely with the privileges of the JVM process. This can lead to full compromise of the affected system. The vulnerability requires no user interaction or privileges and has a network attack vector, making it critical in severity. JDK 17 and later are not vulnerable.
Mitigation Recommendations
Upgrade OpenTelemetry Java Instrumentation to version 2.26.1 or later. If upgrading is not immediately possible and the JVM runs JDK 16 or earlier, disable the RMI instrumentation by setting the system property '-Dotel.instrumentation.rmi.enabled=false'. For JDK 17 and later, no action is required but upgrading is recommended. Red Hat notes that no other mitigations meeting their criteria are currently available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-23T17:06:05.746Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-33701","vendor":"Red Hat"}]
Threat ID: 69c5d2fe3c064ed76ff40486
Added to database: 03/27/2026, 00:44:46 UTC
Last enriched: 08/17/2026, 13:17:01 UTC
Last updated: 09/12/2026, 22:01:33 UTC
Views: 510
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.