CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-33701

Critical · CVSS 9.8

OpenTelemetry Java Instrumentation — Unsafe Java deserialization RCE via RMI instrumentation endpoint

CVSS
9.8
nvd
EPSS
0.93%
57th pct
KEV
No
Class
oss containerizable
CWE-502, CWE-502

Description

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability: First, OpenTelemetry Java instrumentation is attached as a Java agent (`-javaagent`) on Java 16 or earlier. Second, JMX/RMI port has been explicitly configured via `-Dcom.sun.management.jmxremote.port` and is network-reachable. Third, gadget-chain-compatible library is present on the classpath. This results in arbitrary remote code execution with the privileges of the user running the instrumented JVM. For JDK >= 17, no action is required, but upgrading is strongly encouraged. For JDK < 17, upgrade to version 2.26.1 or later. As a workaround, set the system property `-Dotel.instrumentation.rmi.enabled=false` to disable the RMI integration.

Search profile — drives PoC discovery

Symbols RMI instrumentationotel.instrumentation.rmi.enabledcom.sun.management.jmxremote.portjavaagentserialization filtersgadget-chainCWE-502
Keywords CVE-2026-33701OpenTelemetry Java instrumentation RMI deserialization RCEGHSA-xw7x-h9fj-p2c7opentelemetry-java-instrumentation deserializationRMI JMX unsafe deserialization Java agentotel RMI gadget chain exploitopentelemetry-java-instrumentation 2.26.1
Versions: < 2.26.1

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Maven io.opentelemetry.javaagent:opentelemetry-javaagent 0 → 2.26.1

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z