Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39883

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

A flaw was found in OpenTelemetry-Go. On BSD and Solaris platforms, a local attacker could exploit a vulnerability related to the kenv command. By manipulating the system's PATH environment variable, an attacker could achieve arbitrary code execution or privilege escalation, leading to a compromise of system integrity and confidentiality.

Отчет

This is an Important flaw in OpenTelemetry-Go that allows a local attacker to achieve arbitrary code execution or privilege escalation through PATH hijacking. This vulnerability is specific to BSD and Solaris platforms due to the use of the kenv command and does not directly affect Red Hat Enterprise Linux environments. However, the vulnerable component is included in Red Hat products such as Multicluster Engine for Kubernetes.

Дополнительная информация

Статус:

Important
Дефект:
CWE-426
https://bugzilla.redhat.com/show_bug.cgi?id=2456718github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris

EPSS

Процентиль: 12%
0.0022
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

CVSS3: 7
nvd
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

CVSS3: 7
debian
4 месяца назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15. ...

github
4 месяца назад

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

EPSS

Процентиль: 12%
0.0022
Низкий

8.8 High

CVSS3