CVE-2026-33701Disclosure(linuxfoundation / opentelemetry_instrumentation_for_java)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch linuxfoundation opentelemetry_instrumentation_for_java systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, OpenTelemetry Java instrumentation is attached as a Java agent (`-javaagent`) on Java 16 or earlier. Second, JMX/RMI port has been explicitly configured via `-Dcom.sun.management.jmxremote.port` and is network-reachable. Third, gadget-chain-compatible library is present on the classpath. This results in arbitrary remote code execution with the privileges of the user running the instrumented JVM. For JDK >= 17, no action is required, but upgrading is strongly encouraged. For JDK < 17, upgrade to version 2.26.1 or later. As a workaround, set the system property `-Dotel.instrumentation.rmi.enabled=false` to disable the RMI integration.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opentelemetry_instrumentation_for_java

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-03-27); latest day: 2
  • 9 total mentions across 3 days

Affected systems

Products
opentelemetry_instrumentation_for_java

Deep dive

Activity timeline9 mentions / 3d
01345Mentions · 2026-03-27: 5Mentions · 2026-03-30: 2Mentions · 2026-03-31: 2PoC Mentioned / Linked · 2026-03-27: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-30: 2Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 203-2703-3003-31
Signal classification3 categories
Disclosure
555.6%
Patch
333.3%
General
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-275
Disclosure4General1
2026-03-302
Patch2
2026-03-312
Disclosure1Patch1
Full discourse9 posts
  • Gray Hats@the_yellow_fall
    Patch

    OpenTelemetry patches a critical 9.3 RCE flaw (CVE-2026-33701) in its Java agent. Unfiltered RMI deserialization allows full system takeover. Update to 2.26.1 #OpenTelemetry #JavaSecurity #InfoSec #RCE #CVE #DevOps #CyberSecurity #JavaDev #SRE #Monitoring https://securityonline.info/opentelemetry-java-agent-rce-vulnerability-cve-2026-33701/ https://t.co/vryTjblRhv

    Post summary

    The message announces that OpenTelemetry has released patch version 2.26.1 to fix a critical RCE flaw (CVE‑2026‑33701) caused by unfiltered RMI deserialization.

    0801641.1K
    12.3K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『This vulnerability could allow an attacker to perform remote code execution via Object Injection (CAPEC-586).』 CVE-2026-33701 Elastic OTel Java 1.10.0 Security Update (ESA-2026-22 / GHSA-xw7x-h9fj-p2c7) https://discuss.elastic.co/t/elastic-otel-java-1-10-0-security-update-esa-2026-22-ghsa-xw7x-h9fj-p2c7/385700

    Post summary

    The text announces a security update for CVE-2026-33701, describing a remote code execution vulnerability via object injection; no PoC, exploit code, or evidence of active exploitation is provided.

    01000433
    6.7K followersView on X
  • Psychic Lab Ape@psyciclabs
    Patch

    🚨 CVE-2026-33701: OpenTelemetry Java RCE (CVSS 9.3) CWE-502 deserialization flaw in RMI instrumentation. Attacker needs: ✓ JMX/RMI port exposed ✓ Gadget chain on classpath ✓ JDK ≤16 (highest risk) Patch: 2.26.1+ Workaround: -Dotel.instrumentation.rmi.enabled=false

    Post summary

    The post details CVE‑2026‑33701 in OpenTelemetry Java, including its high‑severity vulnerability, required conditions, and supplies a patch (2.26.1+) and a runtime workaround.

    0001045
    19 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical unsafe deserialization flaw in `OpenTelemetry`'s RMI instrumentation (CVE-2026-33701) may lead to RCE. Assess your exposure if using RMI monitoring. #OpenTelemetry #RCE #InfoSec https://www.pulsepatch.io/posts/cve-2026-33701-opentelemetry-rmi-deserialization-rce

    Post summary

    The post alerts to a critical unsafe deserialization flaw in OpenTelemetry’s RMI instrumentation that could result in RCE, but it offers no PoC, exploit details, or patch info.

    0001033
    6 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33701 📊 Severity: 9.3 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33701 #CVE-2026-33701 #CVE #Critical #CyberSecurity #InfoSec https://t.co/EUVkfZ3Tun

    Post summary

    The tweet simply announces CVE-2026-33701 as a critical vulnerability with no further technical, patch, PoC, or exploitation information.

    0001038
    123 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨🚨 Critical OpenTelemetry Java Agent flaw CVE-2026-33701 could lead to remote code execution via unsafe deserialization in RMI instrumentation. 🔗 https://vulert.com/vuln-db/CVE-2026-33701 #CyberSecurity #OpenTelemetry #JavaSecurity #RCE #CVE202633701 #AppSec #DevSecOps #OpenSourceSecurity https://t.co/1CtmcD24K1

    Post summary

    The tweet announces CVE‑2026‑33701 as a critical flaw in the OpenTelemetry Java Agent that could enable remote code execution through unsafe deserialization in its RMI instrumentation, but it provides no proof of concept, exploit code, or patch details.

    0001050
    122 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Critical 9.3 CVSS RCE Vulnerability Hit in OpenTelemetry Java Agent https://securityonline.info/opentelemetry-java-agent-rce-vulnerability-cve-2026-33701/

    Post summary

    The article announces a critical RCE vulnerability (CVSS 9.3) in the OpenTelemetry Java Agent, but provides no PoC, exploit code, or evidence of live exploitation.

    0000045
    241 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33701 OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrument… https://www.cve.org/CVERecord?id=CVE-2026-33701

    Post summary

    CVE-2026-33701 is disclosed as affecting OpenTelemetry Java Instrumentation versions before 2.26.1, with a reference to an RMI instrument issue; no PoC, exploit, or active exploitation is mentioned, but a patch is implied by the versioning information.

    00000124
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33701: OpenTelemetry: Unsafe Deserializ... Classic Java deserialization RCE through OpenTelemetry's RMI endpoint - JDK ≤16 shops with exposed JMX ports are sittin... https://zerodaysignal.com/vulnerability/CVE-2026-33701 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-33701, describing it as a classic Java deserialization RCE affecting OpenTelemetry's RMI endpoint on JDKs ≤16 when JMX ports are exposed, and it links to a site that presumably provides further details or a PoC.

    0000086
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationopentelemetry_instrumentation_for_java---

Explore more