CVE-2026-81192
Deferred Deferred - Pending Action

Untrusted Search Path in OpenTelemetry.Resources.Host on macOS

Vulnerability report for CVE-2026-81192, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: GitHub, Inc.

Description

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable. A local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local code execution/privilege escalation. This vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected. Version 1.16.0-beta.2 contains a patch. No known workarounds are available.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opentelemetry resources_host to 1.16.0-beta.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-426 The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the OpenTelemetry.Resources.Host NuGet package on macOS. It allows a local attacker with less privilege than the host application to manipulate the PATH environment variable or place a malicious binary in a directory that appears before system directories in PATH. This can lead to arbitrary code execution in the application's security context, resulting in local code execution or privilege escalation.

Detection Guidance

Check the installed version of OpenTelemetry.Resources.Host NuGet package. If it is 1.16.0-beta.1 or earlier, the system is vulnerable. Run 'dotnet list package' to inspect versions. On macOS, verify if the application using this package executes 'sh' or 'ioreg' via PATH without absolute paths.

Inspect environment variables for PATH modifications or suspicious directories. Look for unexpected binaries named 'sh' or 'ioreg' in directories listed in PATH before system paths.

Impact Analysis

If you use the affected OpenTelemetry.Resources.Host package on macOS, an attacker with local access could execute arbitrary code on your system with the privileges of the host application. This could lead to unauthorized access, data theft, or further compromise of the system.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Organizations using the affected package may face legal and regulatory penalties due to potential data exposure or loss of integrity.

Mitigation Strategies

Upgrade the OpenTelemetry.Resources.Host NuGet package to version 1.16.0-beta.2 or later. This version uses absolute paths for 'sh' and 'ioreg', removing the PATH dependency.

Review and restrict PATH environment variable settings on macOS systems running the vulnerable package. Ensure no untrusted directories appear before system directories in PATH.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81192. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart