PT-2026-71387 · Opennms · Opennms Meridian+1

CVE-2026-19182

·

Published

2026-08-13

·

Updated

2026-08-13

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenNMS Meridian versions prior to 2024.3.12 OpenNMS Meridian versions prior to 2025.0.9 OpenNMS Horizon versions prior to 36.0.3
Description An incorrect authorization check in the v2 Alarm REST API allows an authenticated user with ROLE REST privileges to acknowledge, escalate, or clear alarms using an arbitrary username. Additionally, users assigned ROLE READONLY can modify the alarm state, bypassing the read-only restriction. This occurs because a credential check intended to restrict these operations is guarded by an inverted condition, preventing it from executing for any non-blank username. This flaw can compromise the integrity of audit records and alarm states.
Recommendations Upgrade Meridian to version 2024.3.12 or newer. Upgrade Meridian to version 2025.0.9 or newer. Upgrade Horizon to version 36.0.3 or newer. Ensure installations are restricted to private networks and not directly accessible from the Internet.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19182

Affected Products

Opennms Horizon
Opennms Meridian