CVE-2026-41433

Source
https://cve.org/CVERecord?id=CVE-2026-41433
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41433.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41433
Aliases
Downstream
Related
Published
2026-04-24T19:26:19.701Z
Modified
2026-08-12T03:51:37.260995934Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H CVSS Calculator
Summary
OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR
Details

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows a local attacker controlling a Java workload to overwrite arbitrary host files when Java injection is enabled and OBI is running with elevated privileges. The injector trusted TMPDIR from the target process and used unsafe file creation semantics, enabling both filesystem boundary escape and symlink-based file clobbering. This vulnerability is fixed in 0.8.0.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-59"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41433.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/open-telemetry/opentelemetry-ebpf-instrumentation

Affected ranges

Type
GIT
Repo
https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:opentelemetry:opentelemetry_ebpf_instrumentation:*:*:*:*:*:go:*:*",
    "extracted_events": [
        {
            "introduced": "0.4.0"
        },
        {
            "fixed": "0.8.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.4.0
v0.4.1
v0.5.0
v0.6.0
v0.7.0
v0.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41433.json"