CVE-2026-19135: OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes

Published Aug 13, 2026
·
Updated

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attacker to gain access to confidential information and compromise integrity.

The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

Affected Software

3 affected components
OpenNMS Opennms Meridian<2024.3.12
OpenNMS Opennms Meridian<2025.0.9
OpenNMS OpenNMS Horizon<36.0.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenNMS Meridian to a version that resolves this vulnerability.

    Fixed in 2024.3.12
  2. Upgrade

    Upgrade OpenNMS Meridian to a version that resolves this vulnerability.

    Fixed in 2025.0.9
  3. Upgrade

    Upgrade OpenNMS Horizon to a version that resolves this vulnerability.

    Fixed in 36.0.3

Event History

Aug 13, 2026
CVE Published
via MITRE·04:47 AM
Data Sourced
via MITRE·04:47 AM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-19135?

CVE-2026-19135 has a medium severity rating of 5.4.

2

How does CVE-2026-19135 affect OpenNMS?

CVE-2026-19135 allows a low-privileged authenticated user to bypass the JEXL expression sandbox in the Measurements REST API and load arbitrary Java classes on the server.

3

Who is affected by CVE-2026-19135?

OpenNMS users with versions of Meridian and Horizon that are vulnerable to this JEXL sandbox bypass are at risk.

4

How can I mitigate CVE-2026-19135?

To mitigate CVE-2026-19135, upgrade to the latest fixed versions of OpenNMS Meridian and Horizon as soon as possible.

5

What kind of attack can CVE-2026-19135 enable?

CVE-2026-19135 can potentially allow an attacker to execute arbitrary code on the server due to class loading capabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203