News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-24051 High · CVSS 7 Low Impact

telemetry/opentelemetry: Arbitrary Code Execution via Untrusted PATH on macOS

Limited exploitability

Exploiting this CVE requires an uncommon setup or configuration. Upgrading is still recommended when possible.

Only affects deployments with OpenTelemetry tracing enabled (telemetry/opentelemetry present in the KrakenD configuration) running on macOS. Linux deployments are not affected. Exploitation also requires local system access and the ability to manipulate the $PATH environment variable.

Component

telemetry/opentelemetry

Disclosed

Mar 9, 2026

CVSS Score

7

Description

The OpenTelemetry Go SDK’s resource detection code invokes the ioreg system command using an unsecured search path on macOS/Darwin. An attacker with local access who can manipulate the $PATH environment variable can substitute a malicious binary and achieve arbitrary code execution. Affects OpenTelemetry-Go SDK versions 1.20.0 through 1.39.0; fixed in 1.40.0.

Version summary

Community Edition

2.13.2

addresses this CVE

Affected CE versions

>= 2.0, < 2.13.2

Enterprise Edition

2.13.0

addresses this CVE

Affected EE versions

>= 2.0, < 2.13.0

Upgrade to the addressed version or later to remediate this vulnerability.

Stay up to date with KrakenD releases and important updates