SQL Injection Vulnerability in OpenNMS Reporting Feature
CVE-2026-89089

6.5MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-89089?

A SQL injection vulnerability exists in the reporting feature of OpenNMS Meridian and Horizon, allowing low-privileged authenticated users to manipulate SQL queries through the reporting REST API. By supplying a DATE_FORMAT parameter, attackers can execute arbitrary SQL commands, potentially accessing sensitive information stored within the database, such as credentials and SNMP community strings. It is crucial for users to upgrade to the latest versions to mitigate this security risk.

Affected Version(s)

Horizon 36.0.0 < 36.0.4

Meridian 2024.1.0 < 2024.3.13

Meridian 2025.0.0 < 2025.0.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xanlar Agamalizade
.