XML External Entity Vulnerability in OpenNMS Meridian and Horizon
CVE-2026-19596
What is CVE-2026-19596?
An XML External Entity (XXE) vulnerability has been identified in the XML collector feature of OpenNMS Meridian and Horizon. This issue arises when the XML parser processes XML from an attacker-supplied source, potentially leading to unauthorized access to sensitive files that belong to the OpenNMS service account, such as database credentials. Additionally, this vulnerability can facilitate out-of-band requests, raising concerns for data security. To mitigate this risk, users should upgrade to the latest versions: Meridian 2024.3.13, 2025.0.10, or Horizon 36.0.4. It's crucial to ensure that these installations are confined to private network environments to prevent Internet exposure.
Affected Version(s)
Horizon 36.0.0 < 36.0.4
Meridian 2024.1.0 < 2024.3.13
Meridian 2025.0.0 < 2025.0.10
