CVE-2026-89054: OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes

Published Sep 10, 2026
·
Updated

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are reachable with no authorization enforced. An unauthenticated attacker able to reach the web UI can disable event definitions and SNMP data collection, suppressing event and alarm generation and stopping metric collection - silently degrading monitoring and detection - with the change persisted and reloaded into the running system.

The solution is to upgrade to Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

Affected Software

1 affected component
OpenNMS OpenNMS Horizon<36.0.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenNMS Horizon to a version that resolves this vulnerability.

    Fixed in 36.0.4

Event History

Sep 10, 2026
CVE Published
via MITRE·07:36 PM
Data Sourced
via MITRE·07:36 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated attacker who can reach the OpenNMS web UI can exploit the affected PATCH endpoints. No credentials or user interaction are required.

2

Are default deployments exposed to the vulnerable endpoints?

The vulnerable authorization policy is part of the shipped /api/v2 REST API configuration, and the affected event-configuration and SNMP data-collection PATCH endpoints are shipped endpoints. Exposure depends on whether an attacker can reach the web UI; installation guidance says OpenNMS should be deployed only on private networks and not directly exposed to the Internet.

3

What can an attacker change, and what is the operational impact?

An attacker can enable or disable event definitions and SNMP data-collection sources. This can suppress event and alarm generation and halt metric collection, silently degrading monitoring and detection; the changes persist and are reloaded by the running system.

4

What should teams do if they cannot upgrade immediately?

Restrict access to the OpenNMS web UI so unauthenticated or untrusted users cannot reach it, particularly from the Internet. The documented remediation is upgrading Horizon to version 36.0.4 or newer.

5

How can administrators identify potential compromise?

Review event-definition and SNMP data-collection source configuration for unexpected enablement or disablement, and investigate unexplained gaps in events, alarms, or metric collection. The affected changes are persisted in configuration and reloaded into the running system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203