In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. An attacker with network access to a JMX or RMI port on an instrumented JVM could exploit this to potentially achieve remote code execution. All three of the following conditions must be true to exploit this vulnerability:
-javaagent)Arbitrary remote code execution with the privileges of the user running the instrumented JVM.
Upgrade to version 2.26.1 or later.
Set the following system property to disable the RMI integration:
-Dotel.instrumentation.rmi.enabled=false
This vulnerability was responsibly disclosed in coordination with Datadog.
{
"cwe_ids": [
"CWE-502"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-25T21:27:43Z",
"nvd_published_at": "2026-03-27T01:16:19Z",
"severity": "CRITICAL"
}