CVE-2026-81192

    Dashboard / Vulnerabilities / CVE-2026-81192

    CVE-2026-81192

    Published: 8 Sept 2026Last Modified: 12 Sept 2026

    Summary: OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS

    Details: `OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable. A local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local code execution/privilege escalation. This vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected. Version 1.16.0-beta.2 contains a patch. No known workarounds are available.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    Instrumentation.Hangfire-1.16.0-beta.2
    Instrumentation.Hangfire-1.16.0-beta.1
    Instrumentation.Hangfire-1.15.1-beta.1
    Instrumentation.Hangfire-1.15.0-beta.1
    Instrumentation.Hangfire-1.14.0-beta.2
    Instrumentation.Hangfire-1.14.0-beta.1
    Instrumentation.Hangfire-1.13.0-beta.1
    Instrumentation.Hangfire-1.12.0-beta.1
    Instrumentation.Hangfire-1.9.0-beta.1
    Instrumentation.Hangfire-1.6.0-beta.1
    Instrumentation.Hangfire-1.5.0-beta.1
    Instrumentation.Hangfire-1.0.0-beta.4
    Instrumentation.Hangfire-1.0.0-beta.3
    Instrumentation.Hangfire-1.0.0-beta.2
    Instrumentation.Hangfire-1.0.0-beta.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-81192 | CVE-DB