CVE-2026-89054High· 8.2▾ TwilightA missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the ship…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are reachable with no authorization enforced. An unauthenticated attacker able to reach the web UI can disable event definitions and SNMP data collection, suppressing event and alarm generation and stopping metric collection - silently degrading monitoring and detection - with the change persisted and reloaded into the running system.
The solution is to upgrade to Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-43002Medium· 5.3An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3
CVE-2014-3474LowOpenStack Horizon Cross-site scripting (XSS) vulnerability
CVE-2016-4428Medium· 5.4OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
CVE-2014-0157MediumOpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
CVE-2014-3473MediumHorizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
CVE-2014-3594LowOpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface