PT-2026-71386 · Opennms · Opennms Meridian+1

·

CVE-2026-19135

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenNMS Meridian versions prior to 2024.3.12 OpenNMS Meridian versions prior to 2025.0.9 OpenNMS Horizon versions prior to 36.0.3
Description A JEXL expression sandbox bypass exists in the Measurements REST API. A low-privileged authenticated user can submit a crafted expression to escape the sandbox and load arbitrary Java classes on the server. This could allow an attacker to access confidential information and compromise system integrity. JEXL (Java Expression Language) is a powerful expression language used to evaluate dynamic expressions in Java applications.
Recommendations Upgrade to Meridian 2024.3.12 or newer. Upgrade to Meridian 2025.0.9 or newer. Upgrade to Horizon 36.0.3 or newer. Ensure the software is installed within private networks and not directly accessible from the Internet.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19135

Affected Products

Opennms Horizon
Opennms Meridian