JEXL Expression Sandbox Bypass in OpenNMS Meridian and Horizon
CVE-2026-19135

5.4MEDIUM

Key Information:

Vendor
CVE Published:
13 August 2026

What is CVE-2026-19135?

A vulnerability exists in multiple versions of OpenNMS Meridian and Horizon that allows low-privileged authenticated users to bypass the JEXL expression sandbox. This issue enables the submission of crafted expressions to the Measurements REST API, which can escape the controlled environment and load arbitrary Java classes on the server. Such exploitation can lead to unauthorized access to sensitive information and potential integrity compromises. Users are advised to upgrade to the latest versions of Meridian (2024.3.12, 2025.0.9) and Horizon (36.0.3) to safeguard against this risk. Additionally, installations of Meridian and Horizon should be restricted to private networks and not be exposed to the Internet directly.

Affected Version(s)

Horizon 36.0.0 < 36.0.3

Meridian 2024.1.0 < 2024.3.12

Meridian 2025.0.0 < 2025.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tinyb0y
Xanlar Agamalizade
.