Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89054— OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes

Quick assessment

Affected
The OpenNMS Group Horizon
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenNMS Horizon 中存在一个缺失授权漏洞,允许在未经身份验证的情况下修改配置。针对 REST API 的 Spring Security 策略为除 PATCH 以外的所有 HTTP 方法定义了授权规则,因此随软件发布的用于事件配置和 SNMP 数据采集的 端点(用于启用或停用事件定义和数据采集源)在未执行任何授权检查的情况下即可访问。能够访问 Web UI 的未认证攻击者可以停用事件定义和 SNMP 数据采集,从而抑制事件和告警生成,并停止指标收集——悄无声息地降低监控和检测能力——且这些变更会被持久

CVSS 8.2 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
The OpenNMS Group Horizon 36.0.0< 36.0.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89054

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes
Source: CVE Program / CVE List V5
Vulnerability Description
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are reachable with no authorization enforced. An unauthenticated attacker able to reach the web UI can disable event definitions and SNMP data collection, suppressing event and alarm generation and stopping metric collection - silently degrading monitoring and detection - with the change persisted and reloaded into the running system. The solution is to upgrade to Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
The OpenNMS Group Horizon 36.0.0 ~ 36.0.4 -

II. Public POCs for CVE-2026-89054

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89054

登录查看更多情报信息。

Patches & Fixes for CVE-2026-89054 (1)

Same Patch Batch · The OpenNMS Group · 2026-09-10 · 3 CVEs total

CVE-2026-89089 6.5 MEDIUM OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parame
CVE-2026-19596 5.9 MEDIUM OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host

IV. Related Vulnerabilities

V. Comments for CVE-2026-89054

No comments yet


Leave a comment