CVE-2026-19135
Received Received - Intake

JEXL Sandbox Bypass in OpenNMS Meridian and Horizon

Vulnerability report for CVE-2026-19135, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: The OpenNMS Group

Description

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
opennms meridian 2024.3.12
opennms meridian 2025.0.9
opennms horizon 36.0.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a JEXL expression sandbox bypass in OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server.

Detection Guidance

Check OpenNMS versions for affected releases (Meridian <2024.3.12, 2025.0.9 or Horizon <36.0.3). Inspect logs for unusual JEXL expression submissions to the Measurements REST API. Monitor for unauthorized Java class loading events.

Impact Analysis

An attacker could gain access to confidential information and compromise system integrity. This could lead to data breaches, unauthorized access to sensitive data, or further system exploitation.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized access to personal or health data. Organizations may face legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade to Meridian 2024.3.12, 2025.0.9 or Horizon 36.0.3 or newer. Ensure OpenNMS instances are not exposed to the internet. Review and restrict access to the Measurements REST API.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19135. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart