A medium-severity vulnerability, assigned CVE-2026-54704 with a CVSS score of 6.5, affects the OpenTelemetry Java Instrumentation JDBC auto-instrumentation component. This flaw occurs when passwords in SQL CONNECT statements are not properly sanitized, specifically when double-quoted, resulting in clear-text database passwords being added to trace span attributes and exported to observability backends via a network attack vector with low user interaction and no required privileges. The business impact of this vulnerability is significant as it allows an attacker to potentially gain high-level access to sensitive information, compromising the confidentiality of the affected system. Affected versions include opentelemetry-javaagent prior to 2.28.0-alpha.
We recommend you to update opentelemetry-javaagent to version 2.28.0-alpha.[/subscribe_to_unlock_form]
A medium-severity vulnerability, assigned CVE-2026-54704 with a CVSS score of 6.5, affects the OpenTelemetry Java Instrumentation JDBC auto-instrumentation component. This flaw occurs when passwords in SQL CONNECT statements are not properly sanitized, specifically when double-quoted, resulting in clear-text database passwords being added to trace span attributes and exported to observability backends via a network attack vector with low user interaction and no required privileges. The business impact of this vulnerability is significant as it allows an attacker to potentially gain high-level access to sensitive information, compromising the confidentiality of the affected system. Affected versions include opentelemetry-javaagent prior to 2.28.0-alpha.
We recommend you to update opentelemetry-javaagent to version 2.28.0-alpha.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]