Skip to main content
EPSS 0.9%top 42%

CVE-2026-33701: CWE-502: Deserialization of Untrusted Data in open-telemetry opentelemetry-java-instrumentation

0
Critical
VulnerabilityCVE-2026-33701cvecve-2026-33701cwe-502gcve
Published: 03/27/2026 (03/27/2026, 00:01:12 UTC)
Source: CVE Database V5
Vendor/Project: open-telemetry
Product: opentelemetry-java-instrumentation

Description

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, OpenTelemetry Java instrumentation is attached as a Java agent (`-javaagent`) on Java 16 or earlier. Second, JMX/RMI port has been explicitly configured via `-Dcom.sun.management.jmxremote.port` and is network-reachable. Third, gadget-chain-compatible library is present on the classpath. This results in arbitrary remote code execution with the privileges of the user running the instrumented JVM. For JDK >= 17, no action is required, but upgrading is strongly encouraged. For JDK < 17, upgrade to version 2.26.1 or later. As a workaround, set the system property `-Dotel.instrumentation.rmi.enabled=false` to disable the RMI integration.

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

open-telemetry

opentelemetry-java-instrumentation

Affected versions
<2.26.1
io.opentelemetry/opentelemetry-java-instrumentation
pkg:maven/io.opentelemetry/opentelemetry-java-instrumentation
Affected versions
<2.26.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 13:17:01 UTC

Technical Analysis

OpenTelemetry Java Instrumentation prior to version 2.26.1 registers a custom RMI endpoint that deserializes incoming data without applying serialization filters, leading to a CWE-502 deserialization of untrusted data vulnerability. On JVMs running JDK 16 or earlier, an attacker with network access to a configured JMX or RMI port can exploit this flaw to achieve remote code execution if a gadget-chain-compatible library is present on the classpath. Exploitation requires three conditions: the Java agent is attached, the JMX/RMI port is network-reachable, and the gadget chain is available. The vulnerability allows arbitrary code execution with the privileges of the JVM process. JDK 17 and later are not affected. The vendor recommends upgrading to version 2.26.1 or later or disabling the RMI instrumentation integration as a workaround. Red Hat's advisory confirms the vulnerability and notes that no complete mitigation meeting their criteria is currently available beyond upgrading or disabling the feature.

Potential Impact

An attacker with network access to a configured JMX or RMI port on an instrumented JVM running JDK 16 or earlier can execute arbitrary code remotely with the privileges of the JVM process. This can lead to full compromise of the affected system. The vulnerability requires no user interaction or privileges and has a network attack vector, making it critical in severity. JDK 17 and later are not vulnerable.

Mitigation Recommendations

Upgrade OpenTelemetry Java Instrumentation to version 2.26.1 or later. If upgrading is not immediately possible and the JVM runs JDK 16 or earlier, disable the RMI instrumentation by setting the system property '-Dotel.instrumentation.rmi.enabled=false'. For JDK 17 and later, no action is required but upgrading is recommended. Red Hat notes that no other mitigations meeting their criteria are currently available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-03-23T17:06:05.746Z
Cvss Version
4.0
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-33701","vendor":"Red Hat"}]

Threat ID: 69c5d2fe3c064ed76ff40486

Added to database: 03/27/2026, 00:44:46 UTC

Last enriched: 08/17/2026, 13:17:01 UTC

Last updated: 09/12/2026, 22:01:33 UTC

Views: 510

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses