CVE-2026-39883
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg comma
CVSS
7.0
Alto
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Publicado: 8 abr 2026 · Última mod.: 14 ago 2026 · CWE-426
0.2%EPSS · 30 días0.3%
2026-08-022026-08-31
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.
- github.comhttp://github.com/open-telemetry/opentelemetry-go/releases/tag/v1.43.0
- github.comhttps://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hfvc-g4fc-pqhx
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:26254
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:26257
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:37387
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:54274
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:54286
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-39883
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2456718
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39883.json
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-828628.4 ALT3.0%
——1Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place malicious files in the workspace to execute arbitrary code during local skill execution.7hCVE-2026-816975.5 MED4.4%
——1openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is reassigned at line 84 to the bare relative name 'crypt_settings.json'. As a result, the legacy Tk GUI's SettingsTab reads and writes KDF settings from crypt_settings.json in the process launch (current working) directory instead of the user's home directory. An attacker who plants a malicious crypt_settings.json (e.g. sha256:1 with all memory-hard KDFs disabled) can silently downgrade encryption performed in that GUI session to roughly one hash round, bypassing the weak-KDF preflight and enabling offline brute-force attacks against the resulting ciphertext. Fixed in 1.4.9.4dCVE-2026-757687.8 ALT6.4%
——2Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.4dCVE-2026-781559.9 CRÍ19.2%
——6privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges3dCVE-2026-55769—43.5%
——13CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role holding DATABASE OWNER could create overloaded built-in operators in the public schema and change the database or role search_path, causing instance-manager introspection queries such as SELECT COUNT(*) > 0 FROM pg_catalog.pg_extension WHERE extname = $1 to execute attacker-controlled functions as the postgres superuser. The same trust issue affected direct sql.Open("pgx", ...) callsites and the public.user_search SECURITY DEFINER function, enabling PostgreSQL superuser access, operating system command execution through COPY ... FROM PROGRAM, and access to the pod ServiceAccount token. This issue is fixed in versions 1.28.4, 1.29.2, and 1.30.0.10dCVE-2026-168697.8 ALT2.4%
——1IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.9d