PT-2026-71387 · Opennms · Opennms Meridian+1
CVE-2026-19182
·
Published
2026-08-13
·
Updated
2026-08-13
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenNMS Meridian versions prior to 2024.3.12
OpenNMS Meridian versions prior to 2025.0.9
OpenNMS Horizon versions prior to 36.0.3
Description
An incorrect authorization check in the v2 Alarm REST API allows an authenticated user with
ROLE REST privileges to acknowledge, escalate, or clear alarms using an arbitrary username. Additionally, users assigned ROLE READONLY can modify the alarm state, bypassing the read-only restriction. This occurs because a credential check intended to restrict these operations is guarded by an inverted condition, preventing it from executing for any non-blank username. This flaw can compromise the integrity of audit records and alarm states.Recommendations
Upgrade Meridian to version 2024.3.12 or newer.
Upgrade Meridian to version 2025.0.9 or newer.
Upgrade Horizon to version 36.0.3 or newer.
Ensure installations are restricted to private networks and not directly accessible from the Internet.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opennms Horizon
Opennms Meridian