CVE-2026-39883 is a PATH hijacking vulnerability affecting OpenTelemetry-Go versions 1.15.0 through 1.42.0. The vulnerability stems from an incomplete fix to CVE-2026-24051, where the BSD kenv command continues to use a bare executable name rather than an absolute path, enabling local attackers to conduct privilege escalation attacks on BSD and Solaris platforms. The issue was resolved in version 1.43.0. The vulnerability carries a CVSS severity rating of 7.0 (HIGH) with a local attack vector requiring low privileges and high attack complexity. Successful exploitation could result in high-impact consequences across confidentiality, integrity, and authenticity, allowing attackers to execute arbitrary code with elevated privileges through PATH manipulation tactics. There is currently no evidence of active exploitation in the wild, with the vulnerability absent from the National Vulnerability Database's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00008 indicates minimal likelihood of exploitation compared to other CVEs, suggesting low community attention and no publicly available exploit code at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.15.0, < 1.43.0CPE matchmatch criteria | cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.