PatchSiren

The OpenNMS Group CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM The OpenNMS Group CVE published 2026-08-13

CVE-2026-19182

CVE-2026-19182 is an incorrect authorization check in OpenNMS Meridian and Horizon that allows low-privileged authenticated users to modify alarm state. This could potentially compromise the integrity of alarm state and audit records. The vulnerability affects OpenNMS Meridian and Horizon deployments, and defenders should assess exposure and prioritize upgrades to prevent potential alarm state tampering. [truncated]

MEDIUM The OpenNMS Group CVE published 2026-08-13

CVE-2026-19135

A low-privileged authenticated user can submit a crafted JEXL expression to the Measurements REST API in OpenNMS Meridian and Horizon, potentially allowing access to confidential information and compromising integrity. The vulnerability allows a low-privileged authenticated user to escape the sandbox and load arbitrary Java classes on the server. Defenders should assess exposure and prioritize upgrades to [truncated]