# Elastic OTel Java 1.10.0 Security Update (ESA-2026-22 / GHSA-xw7x-h9fj-p2c7)

**URL:** <https://discuss.elastic.co/t/elastic-otel-java-1-10-0-security-update-esa-2026-22-ghsa-xw7x-h9fj-p2c7/385700>\
**Category:** Security Announcements\
**Created:** [March 30, 2026, 2:17pm UTC](https://discuss.elastic.co/t/elastic-otel-java-1-10-0-security-update-esa-2026-22-ghsa-xw7x-h9fj-p2c7/385700 "2026-03-30T14:17:53Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![ismisepaul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ismisepaul/32/102235_2.png) [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Post date:** [March 30, 2026, 2:17pm UTC](https://discuss.elastic.co/t/elastic-otel-java-1-10-0-security-update-esa-2026-22-ghsa-xw7x-h9fj-p2c7/385700/1 "2026-03-30T14:17:53Z")

</div>

**Dependency on Vulnerable Third-Party Component in Elastic OTel Java Leading to Remote Code Execution**

Dependency on Vulnerable Third-Party Component (CWE-1395) exists in [Elastic OTel Java](https://github.com/elastic/elastic-otel-java) via a dependency on OpenTelemetry Java instrumentation library. This vulnerability could allow an attacker to perform remote code execution via Object Injection (CAPEC-586). Exploitation requires an attacker with network access to a reachable RMI endpoint on an instrumented JVM that triggers the known vulnerability CVE-2026-33701 / **[GHSA-xw7x-h9fj-p2c7](https://github.com/open-telemetry/opentelemetry-java-instrumentation/security/advisories/GHSA-xw7x-h9fj-p2c7)**.

**Affected Versions:**

- All Elastic OTel Java versions up to and including 1.9.0

**Affected Configurations:**

This vulnerability requires all three of the following conditions to be true:

- Elastic OTel Java is attached to the application as a Java agent (`-javaagent`)
- An RMI endpoint is network-reachable (e.g., JMX remote port, an RMI registry, or any application-exported RMI service)
- A gadget-chain-compatible library is present on the application's classpath

Deployments that do not expose RMI endpoints to the network, or that do not have gadget-chain-compatible libraries on the classpath, are not exploitable.

**Solutions and Mitigations:**

The issue is resolved in version **1.10.0** , which updates the embedded OpenTelemetry Java instrumentation to version 2.26.1.

**For Users that Cannot Upgrade:**

Disable the RMI instrumentation by setting the following JVM system property:

`-Dotel.instrumentation.rmi.enabled=false`

This workaround applies to both self-managed and Kubernetes-based deployments. When using the OpenTelemetry Operator for auto-instrumentation on Kubernetes, this property can be added via the `Instrumentation` object's environment configuration or through the `JAVA_TOOL_OPTIONS` environment variable on the instrumented Pod.

**Indicators of Compromise (IOC)**

Monitor for the following indicators:

- Unexpected inbound network connections to RMI or JMX ports on instrumented JVMs
- Unusual process execution or child processes spawned by the instrumented JVM
- Anomalous deserialization activity in application or JVM logs, particularly stack traces referencing RMI endpoints

**Severity:** CVSSv4.0: Critical ( 9.3 ) - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N  
**CVE ID** : CVE-2026-33701  
**GHSA:** GHSA-xw7x-h9fj-p2c7  
**Problem Type:** CWE-1395 - Dependency on Vulnerable Third-Party Component
