XML External Entity Vulnerability in OpenNMS Meridian and Horizon
CVE-2026-19596

5.9MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-19596?

An XML External Entity (XXE) vulnerability has been identified in the XML collector feature of OpenNMS Meridian and Horizon. This issue arises when the XML parser processes XML from an attacker-supplied source, potentially leading to unauthorized access to sensitive files that belong to the OpenNMS service account, such as database credentials. Additionally, this vulnerability can facilitate out-of-band requests, raising concerns for data security. To mitigate this risk, users should upgrade to the latest versions: Meridian 2024.3.13, 2025.0.10, or Horizon 36.0.4. It's crucial to ensure that these installations are confined to private network environments to prevent Internet exposure.

Affected Version(s)

Horizon 36.0.0 < 36.0.4

Meridian 2024.1.0 < 2024.3.13

Meridian 2025.0.0 < 2025.0.10

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Keith Lee, Foregenix
.