CVE-2026-81192
Last modified
CVE-2026-81192 is a high-severity vulnerability rated 7/10 on the CVSS scale. `OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable. A local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local code execution/privilege escalation. This vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected. Version 1.16.0-beta.2 contains a patch. No known workarounds are available.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| open-telemetry | opentelemetry-dotnet-contrib | < 1.16.0-beta.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-81192?
How severe is CVE-2026-81192?
How do I fix CVE-2026-81192?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81167Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2026-81168Authentication Bypass Using an Alternate Path or Channel vul…3.7
- CVE-2026-8117A security vulnerability has been detected in SourceCodester…4.3
- CVE-2026-81176Svelte devalue is a JavaScript library that serializes value…5.3
- CVE-2026-8118The Royal Addons for Elementor – Addons and Templates Kit fo…6.5
- CVE-2026-8119A vulnerability was detected in Open5GS up to 2.7.7. Impacte…5.5
- CVE-2026-81194The MasterStudy LMS WordPress Plugin WordPress plugin befor…4.3
- CVE-2026-81195The MasterStudy LMS WordPress Plugin WordPress plugin befor…5.3
- CVE-2026-81196The MasterStudy LMS WordPress Plugin WordPress plugin befor…2.7
- CVE-2026-81197The MasterStudy LMS WordPress Plugin WordPress plugin befor…5.3
- CVE-2026-81198The MasterStudy LMS WordPress Plugin WordPress plugin befor…3.8
- CVE-2026-81199The MasterStudy LMS WordPress Plugin WordPress plugin befor…5.3
Are you affected by CVE-2026-81192?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
