← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 13, 2026 · 05:17via CVEFeed

CVE-2026-19182 - OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only

Brief

CVE ID : CVE-2026-19182

Published : Aug. 13, 2026, 5:17 a. m.

  • 3 hours, 47 minutes ago

Description : An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction.

A credential check that should restrict these operations is guarded by an inverted condition, so it never executes for a real (non-blank) username. This can potentially allow an attacker to compromise the integrity of alarm state and audit records.

The solution is to upgrade to Meridian 2024.

  • 12, 2025.
  • 9 and Horizon 36.
  • 3 or newer.
Read more on CVEFeed