CRITICALMaven

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution

CVE-2026-33701Published 4 months agoUpdated 1 week agoSource: OSV

Affected packages

  • io.opentelemetry.javaagent:opentelemetry-javaagentbefore 2.26.1

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.93%
EPSS percentile
57.3%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 57%.

OpenTelemetry: Unsafe Deserialization in RMI Instrumentation may Lead to Remote Code Execution | HackTribune