PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19182 The OpenNMS Group CVE debrief

CVE-2026-19182 is an incorrect authorization check in OpenNMS Meridian and Horizon that allows low-privileged authenticated users to modify alarm state. This could potentially compromise the integrity of alarm state and audit records. The vulnerability affects OpenNMS Meridian and Horizon deployments, and defenders should assess exposure and prioritize upgrades to prevent potential alarm state tampering. The solution involves upgrading to specific versions of Meridian and Horizon. Affected deployments require verification of user access controls and remediation priority.

Vendor
The OpenNMS Group
Product
Meridian
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-08
Advisory published
2026-08-13
Advisory updated
2026-09-08

Who should care

Defenders responsible for OpenNMS Meridian and Horizon deployments should assess exposure and prioritize upgrades to prevent potential alarm state tampering. Affected deployments require verification of user access controls and remediation priority. Defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. Security teams and vulnerability management teams should track exceptions, retest remedi

Why it matters

CVE-2026-19182 allows low-privileged authenticated users to modify alarm state in OpenNMS Meridian and Horizon, potentially compromising integrity and audit records. Defenders should prioritize upgrades to fixed versions to prevent potential alarm state tampering. Affected deployments require verification of user access controls and remediation priority.

  • Potential compromise of alarm state integrity.
  • Potential tampering with audit records.
  • Verification of user access controls required.
  • Remediation priority for affected deployments.

Technical summary

An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows low-privileged authenticated users to modify alarm state. This vulnerability could potentially compromise the integrity of alarm state and audit records. The solution involves upgrading to specific versions of Meridian and Horizon. Defenders should prioritize upgrades to fixed versions to prevent potential alarm state tampering. The vulnerability affects OpenNMS Meridian and Horizon deployments, and defenders should assess exposure and prioritize upgrades.

Defensive priority

Defenders should prioritize upgrading to fixed versions of OpenNMS Meridian and Horizon to prevent potential alarm state tampering.

Recommended defensive actions

  • Upgrade to Meridian 2024.3.12, 2025.0.9 or newer.
  • Upgrade to Horizon 36.0.3 or newer.
  • Restrict access to the v2 Alarm REST API.
  • Monitor for suspicious alarm state modifications.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the incorrect authorization check in OpenNMS Meridian and Horizon, allowing low-privileged users to modify alarm state. The vulnerability has been publicly disclosed, and defenders should verify the affected scope and severity. The evidence is limited to the information provided in the CVE record and NVD entry. Defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19182 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19182

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19182 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19182

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.