(providing more detailed references)
POSIX specifically calls out that it doesn't guarantee that the path is "/bin/sh":
107271 Applications should note that the standard PATH to the shell cannot be assumed to be either
107272 /bin/sh or /usr/bin/sh, and should be determined by interrogation of the PATH returned by
107273 getconf PATH, ensuring that the returned pathname is an absolute pathname and not a shell
107274 built-in.
https://pubs.opengroup.org/onlinepubs/9699919799/utilities/s...POSIX mentions "#!" several times, but doesn't require it; saying things like "on systems that support executable scripts (the "#!" construct)".
As the lack of a hard-codable path is frustrating, it recommends setting the shebang at install-time:
107279 Furthermore, on systems that support executable scripts (the "#!" construct), it is
107280 recommended that applications using executable scripts install them using getconf PATH to
107281 determine the shell pathname and update the "#!" script appropriately as it is being installed
107282 (for example, with sed). For example: