PatchSiren cyber security CVE debrief
CVE-2026-19182 The OpenNMS Group CVE debrief
CVE-2026-19182 is an incorrect authorization check in OpenNMS Meridian and Horizon that allows low-privileged authenticated users to modify alarm state. This could potentially compromise the integrity of alarm state and audit records. The vulnerability affects OpenNMS Meridian and Horizon deployments, and defenders should assess exposure and prioritize upgrades to prevent potential alarm state tampering. The solution involves upgrading to specific versions of Meridian and Horizon. Affected deployments require verification of user access controls and remediation priority.
- Vendor
- The OpenNMS Group
- Product
- Meridian
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-13
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-13
- Advisory updated
- 2026-09-08
Who should care
Defenders responsible for OpenNMS Meridian and Horizon deployments should assess exposure and prioritize upgrades to prevent potential alarm state tampering. Affected deployments require verification of user access controls and remediation priority. Defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. Security teams and vulnerability management teams should track exceptions, retest remedi
Why it matters
CVE-2026-19182 allows low-privileged authenticated users to modify alarm state in OpenNMS Meridian and Horizon, potentially compromising integrity and audit records. Defenders should prioritize upgrades to fixed versions to prevent potential alarm state tampering. Affected deployments require verification of user access controls and remediation priority.
- Potential compromise of alarm state integrity.
- Potential tampering with audit records.
- Verification of user access controls required.
- Remediation priority for affected deployments.
Technical summary
An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows low-privileged authenticated users to modify alarm state. This vulnerability could potentially compromise the integrity of alarm state and audit records. The solution involves upgrading to specific versions of Meridian and Horizon. Defenders should prioritize upgrades to fixed versions to prevent potential alarm state tampering. The vulnerability affects OpenNMS Meridian and Horizon deployments, and defenders should assess exposure and prioritize upgrades.
Defensive priority
Defenders should prioritize upgrading to fixed versions of OpenNMS Meridian and Horizon to prevent potential alarm state tampering.
Recommended defensive actions
- Upgrade to Meridian 2024.3.12, 2025.0.9 or newer.
- Upgrade to Horizon 36.0.3 or newer.
- Restrict access to the v2 Alarm REST API.
- Monitor for suspicious alarm state modifications.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the incorrect authorization check in OpenNMS Meridian and Horizon, allowing low-privileged users to modify alarm state. The vulnerability has been publicly disclosed, and defenders should verify the affected scope and severity. The evidence is limited to the information provided in the CVE record and NVD entry. Defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19182 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19182
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19182 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19182
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenNMS/opennms/pull/8755
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.