Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39883

32
FAUCET Score

CVE-2026-39883 is a PATH hijacking vulnerability affecting OpenTelemetry-Go versions 1.15.0 through 1.42.0. The vulnerability stems from an incomplete fix to CVE-2026-24051, where the BSD kenv command continues to use a bare executable name rather than an absolute path, enabling local attackers to conduct privilege escalation attacks on BSD and Solaris platforms. The issue was resolved in version 1.43.0. The vulnerability carries a CVSS severity rating of 7.0 (HIGH) with a local attack vector requiring low privileges and high attack complexity. Successful exploitation could result in high-impact consequences across confidentiality, integrity, and authenticity, allowing attackers to execute arbitrary code with elevated privileges through PATH manipulation tactics. There is currently no evidence of active exploitation in the wild, with the vulnerability absent from the National Vulnerability Database's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00008 indicates minimal likelihood of exploitation compared to other CVEs, suggesting low community attention and no publicly available exploit code at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.15.0, < 1.43.0CPE matchmatch criteria
cpe:2.3:a:opentelemetry:opentelemetry:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 4.0

7.3HIGH

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 39th percentile among its peer group of 1,516 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: go.opentelemetry.io/otel/sdkFixed in: 1.43.0

Vendor Advisories (1)

goGHSA-hfvc-g4fc-pqhxhigh

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

Apr 8, 2026

References

access.redhat.com / errata/RHSA-2026:26254
access.redhat.com / errata/RHSA-2026:26257
access.redhat.com / errata/RHSA-2026:37387
access.redhat.com / security/cve/CVE-2026-39883
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-39883.json
github.com / open-telemetry/opentelemetry-go/releases/tag/v1.43.0
Release Notes
github.com / open-telemetry/opentelemetry-go/security/advisories/GHSA-hfvc-g4fc-pqhx
ExploitThird Party Advisory