CVE-2026-33701 is a critical deserialization vulnerability affecting OpenTelemetry Java Instrumentation versions prior to 2.26.1, specifically when deployed as a Java agent on JDK 16 or earlier. This flaw allows an unauthenticated attacker with network access to a JMX/RMI port to achieve remote code execution (RCE) with the privileges of the instrumented JVM, provided a gadget-chain library is present. Rated 9.3 CRITICAL, the vulnerability has a low attack complexity and requires no user interaction for exploitation. While there is no known active exploitation or public exploit code available (Metasploit, Nuclei, ExploitDB), it has received some community discussion and alerts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.26.1CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:opentelemetry_instrumentation_for_java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.