PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19596 The OpenNMS Group CVE debrief

An XML External Entity (XXE) vulnerability exists in OpenNMS Meridian and Horizon. When OpenNMS collects XML from an attacker-controlled source, the collector's XML parser resolves external entities and external DTDs, allowing an attacker to read files accessible to the OpenNMS service account and induce out-of-band requests. The vulnerability can be mitigated by upgrading to patched versions and restricting access to OpenNMS installations. This requires immediate attention from OpenNMS administrators and security teams to assess exposure and take necessary actions.

Vendor
The OpenNMS Group
Product
Meridian
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-18
Advisory published
2026-09-10
Advisory updated
2026-09-18

Who should care

OpenNMS administrators and security teams should assess exposure and upgrade to patched versions. They should also verify installation access controls and monitor for suspicious activity. Additionally, they should review compensating controls for exposed systems and track exceptions and retest remediated assets. Security teams should prioritize the vulnerability and implement necessary mitigations to prevent exploitation.

Why it matters

The XXE vulnerability in OpenNMS Meridian and Horizon allows attackers to read files and induce out-of-band requests when collecting XML from controlled sources. OpenNMS administrators and security teams should assess exposure, verify installation access controls, and upgrade to patched versions.

  • Potential unauthorized file reads
  • Possible out-of-band requests induced by attackers
  • Verification of OpenNMS installation access controls required
  • Upgrade to patched versions prioritized

Technical summary

The OpenNMS Meridian and Horizon XML collector is vulnerable to XXE attacks when collecting XML from attacker-controlled sources. This allows an attacker to read files accessible to the OpenNMS service account and induce out-of-band requests. The vulnerability can be mitigated by upgrading to patched versions and restricting access to OpenNMS installations. Technical teams should review the vulnerability and implement necessary mitigations to prevent exploitation. The vulnerability is caused by the XML parser resolving external entities and external DTDs, which can be exploited by attackers to gain unauthorized access to sensitive data.

Defensive priority

Upgrade to Meridian 2024.3.13, 2025.0.10, or Horizon 36.0.4, and restrict OpenNMS installation access.

Recommended defensive actions

  • Upgrade to Meridian 2024.3.13, 2025.0.10, or Horizon 36.0.4
  • Restrict access to OpenNMS installations
  • Monitor for suspicious XML collection activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the XXE vulnerability in OpenNMS Meridian and Horizon. The vulnerability allows attackers to read files and induce out-of-band requests when collecting XML from controlled sources. OpenNMS administrators and security teams should assess exposure, verify installation access controls, and upgrade to patched versions. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19596 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19596

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19596 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19596

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.