In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. An attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability:
-javaagent)Arbitrary remote code execution with the privileges of the user running the instrumented JVM.
Upgrade to version 2.26.1 or later.
Set the following system property to disable the RMI integration:
-Dotel.instrumentation.rmi.enabled=false
{
"cwe_ids": [
"CWE-1395",
"CWE-502"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-26T17:22:53Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}