OpenNMS Horizon 中存在一个缺失授权漏洞,允许在未经身份验证的情况下修改配置。针对 REST API 的 Spring Security 策略为除 PATCH 以外的所有 HTTP 方法定义了授权规则,因此随软件发布的用于事件配置和 SNMP 数据采集的 端点(用于启用或停用事件定义和数据采集源)在未执行任何授权检查的情况下即可访问。能够访问 Web UI 的未认证攻击者可以停用事件定义和 SNMP 数据采集,从而抑制事件和告警生成,并停止指标收集——悄无声息地降低监控和检测能力——且这些变更会被持久
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| The OpenNMS Group | Horizon | 36.0.0< 36.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The OpenNMS Group | Horizon | 36.0.0 ~ 36.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89089 | 6.5 MEDIUM | OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parame |
| CVE-2026-19596 | 5.9 MEDIUM | OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host |
No comments yet