CVE-2026-19182
Received Received - Intake

Incorrect Authorization Check in OpenNMS Meridian and Horizon Allows Alarm State Manipulation

Vulnerability report for CVE-2026-19182, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: The OpenNMS Group

Description

An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction. A credential check that should restrict these operations is guarded by an inverted condition, so it never executes for a real (non-blank) username. This can potentially allow an attacker to compromise the integrity of alarm state and audit records. The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
opennms meridian 2024.3.12
opennms meridian 2025.0.9
opennms horizon 36.0.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon. A low-privileged authenticated user with ROLE_REST can acknowledge, escalate, or clear alarms as any user. If also assigned ROLE_READONLY, they can modify alarm state despite read-only restrictions. The issue stems from an inverted condition in the credential check, bypassing restrictions for non-blank usernames.

Impact Analysis

An attacker could manipulate alarm states and audit records, potentially compromising system integrity. This may lead to false alarms being cleared or critical alarms being ignored, affecting monitoring and response processes. The impact is limited to authenticated users with specific roles.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized modifications to audit records, potentially violating integrity requirements in GDPR and HIPAA. Accurate audit trails are essential for these regulations, and this flaw undermines their reliability.

Mitigation Strategies

Upgrade to Meridian 2024.3.12, 2025.0.9 or Horizon 36.0.3 or newer to address the incorrect authorization check in the v2 Alarm REST API.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19182. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart