The OpenNMS Group has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.5 (medium). Most affected products: Meridian (2), Horizon (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-89054High· 8.2A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication45CVE-2026-89089Medium· 6.5A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon36CVE-2026-19596Medium· 5.9An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon32
The OpenNMS Group vulnerabilities
CVEs affecting The OpenNMS Group, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-89089Medium· 6.5A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon
A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports "…
CVE-2026-19596Medium· 5.9An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon
An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon. When OpenNMS collects XML from a source whose response is attacker-controlled (for example a compromised monitor…
CVE-2026-89054High· 8.2A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the ship…