AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19182

MEDIUM · CVSS 4.3 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The v2 Alarm REST API in OpenNMS Meridian and Horizon is vulnerable due to an incorrect authorization check, allowing low-privileged users to manipulate alarm states and audit records under arbitrary usernames. This flaw could compromise the integrity of alarm management, making it critical for organizations using these systems to prioritize upgrades to the specified secure versions. Users with roles that interact with the API should take immediate action to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19182
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%

Original NVD Description

An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction. A credential check that should restrict these operations is guarded by an inverted condition, so it never executes for a real (non-blank) username. This can potentially allow an attacker to compromise the integrity of alarm state and audit records. The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.