Description
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are reachable with no authorization enforced. An unauthenticated attacker able to reach the web UI can disable event definitions and SNMP data collection, suppressing event and alarm generation and stopping metric collection - silently degrading monitoring and detection - with the change persisted and reloaded into the running system.



The solution is to upgrade to Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Published: 2026-09-10
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration changes that silence monitoring and alerts by disabling event definitions and SNMP data collection
Action: Patch Immediately
AI Analysis

Impact

A missing authorization check on PATCH endpoints in the /api/v2 REST API of OpenNMS Horizon allows an unauthenticated attacker who can reach the web UI to invoke configuration actions without credentials. Through these endpoints, an attacker can enable or disable event definitions and SNMP data‑collection sources, causing the system to stop generating alarms and metrics and effectively silencing alerts without any indication to administrators.

Affected Systems

The flaw affects installations of OpenNMS Horizon prior to version 36.0.4. All Horizon deployments that expose the /api/v2 REST endpoints, such as the36.0.3 releases, are vulnerable. The vendor’s installation guidelines state that Horizon should run within private networks and should not be directly exposed to the Internet.

Risk and Exploitability

The vulnerability receives a CVSS score of 8.2, classifying it as high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is the web interface; an attacker must have network reach to the Horizon server to exploit the unauthenticated PATCH calls. Due to the absence of denial of monitoring services, which can have serious operational impact in a production environment.

Generated by OpenCVE AI on September 10, 2026 at 23:15 UTC.

Remediation

Vendor Solution

Upgrade to Horizon 36.0.4 or newer.


OpenCVE Recommended Actions

  • Upgrade OpenNMS Horizon to version 36.0.4 or newer to address the missing authorization check on PATCH endpoints.
  • Ensure Horizon is deployed behind a firewall and that the /api/v2 REST interface is only accessible from trusted internal networks; block public access to prevent unauthenticated use.
  • Enable comprehensive logging of all PATCH requests and regularly audit logs for unexpected changes to event definitions and SNMP data collection sources.

Generated by OpenCVE AI on September 10, 2026 at 23:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared The Opennms Group
The Opennms Group horizon
Vendors & Products The Opennms Group
The Opennms Group horizon

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are reachable with no authorization enforced. An unauthenticated attacker able to reach the web UI can disable event definitions and SNMP data collection, suppressing event and alarm generation and stopping metric collection - silently degrading monitoring and detection - with the change persisted and reloaded into the running system. The solution is to upgrade to Horizon 36.0.4 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Title OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

The Opennms Group Horizon
cve-icon MITRE

Status: PUBLISHED

Assigner: OpenNMS

Published:

Updated: 2026-09-10T20:03:12.742Z

Reserved: 2026-09-10T17:29:48.545Z

Link: CVE-2026-89054

cve-icon Vulnrichment

Updated: 2026-09-10T20:03:10.007Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T20:17:31.973

Modified: 2026-09-18T19:21:34.307

Link: CVE-2026-89054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:59:48Z

Weaknesses