OpenTelemetry-Go PATH Hijacking via ioreg/kenv (<=1.42.0)
CVE-2026-39883 Published on April 8, 2026
OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using absolute path enables PATH hijacking
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.
Vulnerability Analysis
CVE-2026-39883 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is an Untrusted Path Vulnerability?
The application searches for critical resources using an externally-supplied search path that can point to resources that are not under the application's direct control.
CVE-2026-39883 has been classified to as an Untrusted Path vulnerability or weakness.
Products Associated with CVE-2026-39883
stack.watch emails you whenever new vulnerabilities are published in Red Hat Multicluster Engine or Red Hat Openshift Data Foundation. Just hit a watch button to start following.
Affected Versions
open-telemetry opentelemetry-go:- Version >= 1.15.0, < 1.43.0 is affected.
- Version 1781539691 and below * is unaffected.
- Version 1781539725 and below * is unaffected.
- Version 1782932114 and below * is unaffected.
- Version 1782931768 and below * is unaffected.
- Version 1782932104 and below * is unaffected.
- Version 1783536000 and below * is unaffected.
- Version 1783535989 and below * is unaffected.
- Version 1783536515 and below * is unaffected.
- Version 1782932521 and below * is unaffected.
- Version 1783018461 and below * is unaffected.
- Version 1783018421 and below * is unaffected.
- Version 1782932812 and below * is unaffected.
- Version 1783537001 and below * is unaffected.
- Version 1782932919 and below * is unaffected.
- Version 1783537586 and below * is unaffected.
- Version 1782932969 and below * is unaffected.
- Version 1782933015 and below * is unaffected.
- Version 1782933042 and below * is unaffected.
- Version 1783537392 and below * is unaffected.
- Version 1782933235 and below * is unaffected.
- Version 1782933251 and below * is unaffected.
- Version 1783537955 and below * is unaffected.
- Version 1782933417 and below * is unaffected.
- Version 1783537742 and below * is unaffected.
- Version 1782933602 and below * is unaffected.
- Version 1783019377 and below * is unaffected.
- Version 1782934054 and below * is unaffected.
- Version 1782934036 and below * is unaffected.
- Version 1782934284 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.