Threat Advisory

OpenTelemetry Java Instrumentation Fails to Sanitize Database Passwords

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, assigned CVE-2026-54704 with a CVSS score of 6.5, affects the OpenTelemetry Java Instrumentation JDBC auto-instrumentation component. This flaw occurs when passwords in SQL CONNECT statements are not properly sanitized, specifically when double-quoted, resulting in clear-text database passwords being added to trace span attributes and exported to observability backends via a network attack vector with low user interaction and no required privileges. The business impact of this vulnerability is significant as it allows an attacker to potentially gain high-level access to sensitive information, compromising the confidentiality of the affected system. Affected versions include opentelemetry-javaagent prior to 2.28.0-alpha.

RECOMMENDATION:

We recommend you to update opentelemetry-javaagent to version 2.28.0-alpha.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability, assigned CVE-2026-54704 with a CVSS score of 6.5, affects the OpenTelemetry Java Instrumentation JDBC auto-instrumentation component. This flaw occurs when passwords in SQL CONNECT statements are not properly sanitized, specifically when double-quoted, resulting in clear-text database passwords being added to trace span attributes and exported to observability backends via a network attack vector with low user interaction and no required privileges. The business impact of this vulnerability is significant as it allows an attacker to potentially gain high-level access to sensitive information, compromising the confidentiality of the affected system. Affected versions include opentelemetry-javaagent prior to 2.28.0-alpha.

RECOMMENDATION:

We recommend you to update opentelemetry-javaagent to version 2.28.0-alpha.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu