目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-89054— OpenNMS /api/v2补丁接口未授权配置修改漏洞

一分钟漏洞结论

影响对象
The OpenNMS Group Horizon
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

OpenNMS Horizon 中存在一个缺失授权漏洞,允许在未经身份验证的情况下修改配置。针对 REST API 的 Spring Security 策略为除 PATCH 以外的所有 HTTP 方法定义了授权规则,因此随软件发布的用于事件配置和 SNMP 数据采集的 端点(用于启用或停用事件定义和数据采集源)在未执行任何授权检查的情况下即可访问。能够访问 Web UI 的未认证攻击者可以停用事件定义和 SNMP 数据采集,从而抑制事件和告警生成,并停止指标收集——悄无声息地降低监控和检测能力——且这些变更会被持久

CVSS 8.2 · High

影响版本矩阵 1

厂商产品 版本范围状态
The OpenNMS Group Horizon 36.0.0< 36.0.4 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-89054 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes
来源: CVE Program / CVE List V5
Vulnerability Description
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are reachable with no authorization enforced. An unauthenticated attacker able to reach the web UI can disable event definitions and SNMP data collection, suppressing event and alarm generation and stopping metric collection - silently degrading monitoring and detection - with the change persisted and reloaded into the running system. The solution is to upgrade to Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
The OpenNMS Group Horizon 36.0.0 ~ 36.0.4 -

二、漏洞 CVE-2026-89054 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-89054 的情报信息

登录查看更多情报信息。

CVE-2026-89054 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89054

暂无评论


发表评论