SQL Injection Vulnerability in OpenNMS Reporting Feature
CVE-2026-89089
6.5MEDIUM
What is CVE-2026-89089?
A SQL injection vulnerability exists in the reporting feature of OpenNMS Meridian and Horizon, allowing low-privileged authenticated users to manipulate SQL queries through the reporting REST API. By supplying a DATE_FORMAT parameter, attackers can execute arbitrary SQL commands, potentially accessing sensitive information stored within the database, such as credentials and SNMP community strings. It is crucial for users to upgrade to the latest versions to mitigate this security risk.
Affected Version(s)
Horizon 36.0.0 < 36.0.4
Meridian 2024.1.0 < 2024.3.13
Meridian 2025.0.0 < 2025.0.10
