Impact
A faulty authorization check in the v2 Alarm REST API of OpenNMS allows an authenticated user with the ROLE_REST privilege to acknowledge, elevate, or clear alarms recorded under any username. When the user also possesses ROLE_READONLY, the same vulnerability permits changes to alarm state even though read‑only access is intended. This flaw gives the attacker the ability to alter alarm data and audit records, potentially compromising the integrity and trustworthiness of the monitoring system.
Affected Systems
All installations of OpenNMS Meridian and Horizon running versions older than Meridian 2024.3.12, 2025.0.9 or Horizon 36.0.3 are affected. These products are distributed by The OpenNMS Group under the Horizon and Meridian brands.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity vulnerability. No EPSS score is available, so the likelihood of exploitation cannot be quantified from current data. The vulnerability is not listed in CISA’s KEV catalog. Attackers must have authenticated access to the REST API, typically within an organization’s private network, and possess the ROLE_REST privilege to exploit the flaw. Because the check is inverted, the condition is never enforced for genuine users, which means the flaw is always present for the targeted roles.
OpenCVE Enrichment