CVE-2026-24051
High
· CVSS 7
Low ImpactExploiting this CVE requires an uncommon setup or configuration. Upgrading is still recommended when possible.
telemetry/opentelemetry present in the KrakenD configuration) running on macOS.
Linux deployments are not affected. Exploitation also requires local system access and
the ability to manipulate the $PATH environment variable.Component
telemetry/opentelemetry
Disclosed
Mar 9, 2026
CVSS Score
7
ioreg system command
using an unsecured search path on macOS/Darwin. An attacker with local access who can
manipulate the $PATH environment variable can substitute a malicious binary and
achieve arbitrary code execution. Affects OpenTelemetry-Go SDK versions 1.20.0 through
1.39.0; fixed in 1.40.0.Community Edition
2.13.2
addresses this CVE
Affected CE versions
>= 2.0, < 2.13.2
Enterprise Edition
2.13.0
addresses this CVE
Affected EE versions
>= 2.0, < 2.13.0
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates