Impact
The vulnerability is a JEXL expression sandbox bypass that allows a low‑privileged authenticated user to submit a crafted expression to the Measurements REST API and escape the sandbox. By loading arbitrary Java classes on the server, the attacker could read confidential data and modify data integrity of the OpenNMS installation. This flaw represents a form of code execution or privilege escalation within the application context.
Affected Systems
The vulnerability affects multiple versions of OpenNMS Meridian and Horizon distributed by The OpenNMS Group. The exact impacted releases are not enumerated in the data, but the vendor’s guidance says upgrading to Meridian 2024.3.12, 2025.0.9 or Horizon 36.0.3 or newer removes the issue.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, so a concrete exploitation probability cannot be determined, but the flaw requires an authenticated ROLE_USER, so it is likely limited to internal users or compromised accounts. The vulnerability is not listed in the CISA KEV catalog. Exploitation would involve submitting a crafted expression to the Measurements REST API over HTTP/HTTPS; an attacker must therefore have network access to the application and valid credentials.
OpenCVE Enrichment