Browse all 16 CVE security advisories affecting The OpenNMS Group. AI-powered Chinese analysis, POCs, and references for each vulnerability.
The OpenNMS Group develops enterprise-grade network monitoring and management solutions, primarily serving organizations requiring comprehensive infrastructure visibility. Historically, their products have been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and authentication flaws. While no major public security incidents have been widely documented, the 11 CVEs on record highlight ongoing security challenges in areas like API endpoints and web interfaces. The organization has typically addressed these issues through timely patches and security advisories, though the persistence of certain vulnerability classes suggests a need for continued focus on secure coding practices and comprehensive input sanitization across their product lines.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-89089 | OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER) — Meridian CWE-89 | 6.5 | Medium | 2026-09-10 |
| CVE-2026-19596 | OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host — Meridian CWE-611 | 5.9 | Medium | 2026-09-10 |
| CVE-2026-19182 | OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only — Meridian CWE-863 | 4.3 | Medium | 2026-08-13 |
| CVE-2026-19135 | OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes — Meridian CWE-470 | 5.4 | Medium | 2026-08-13 |
| CVE-2023-0867 | Multiple stored and reflected Cross-site Scripting in webapp — Meridian CWE-79 | 6.7 | Medium | 2023-02-23 |
| CVE-2023-0868 | Stealing Cookies using Reflected XSS via graph results — Meridian CWE-20 | 6.7 | Medium | 2023-02-23 |
This page lists every published CVE security advisory associated with The OpenNMS Group. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.