Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89089— OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER)

Quick assessment

Affected
The OpenNMS Group Meridian
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenNMS Meridian 和 Horizon 的多个版本中,基于 JasperReports 的报告功能存在 SQL 注入漏洞。一个低权限的已认证用户(ROLE_USER)可以通过报告 REST API(POST /rest/reports/{id})运行系统默认启用且预置的在线报告“维护合同已过期”(AssetManagementMaintExpired)和“维护合同策略”(AssetManagementMaintStrategy)。攻击者可以提供一个 DATE_FORMAT 参数,而报告模板会将其原样、

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89089

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER)
Source: CVE Program / CVE List V5
Vulnerability Description
A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports "Maintenance contracts expired" (AssetManagementMaintExpired) and "Maintenance contracts strategy" (AssetManagementMaintStrategy) via the reporting REST API (POST /rest/reports/{id}) and supply a DATE_FORMAT parameter that the report templates substitute literally, un-escaped, into their SQL queries. This lets an attacker execute arbitrary SQL against the OpenNMS database and read arbitrary data, including database-stored secrets such as provisioning and notification credentials and SNMP community strings. The solution is to upgrade to Meridian 2024.3.13, 2025.0.10 and Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
The OpenNMS Group Meridian 2024.1.0 ~ 2024.3.13 -
The OpenNMS Group Horizon 36.0.0 ~ 36.0.4 -

II. Public POCs for CVE-2026-89089

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89089

登录查看更多情报信息。

Patches & Fixes for CVE-2026-89089 (1)

Same Patch Batch · The OpenNMS Group · 2026-09-10 · 3 CVEs total

CVE-2026-89054 8.2 HIGH OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configurat
CVE-2026-19596 5.9 MEDIUM OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host

IV. Related Vulnerabilities

V. Comments for CVE-2026-89089

No comments yet


Leave a comment