Impact
A missing authorization check on PATCH endpoints in the /api/v2 REST API of OpenNMS Horizon allows an unauthenticated attacker who can reach the web UI to invoke configuration actions without credentials. Through these endpoints, an attacker can enable or disable event definitions and SNMP data‑collection sources, causing the system to stop generating alarms and metrics and effectively silencing alerts without any indication to administrators.
Affected Systems
The flaw affects installations of OpenNMS Horizon prior to version 36.0.4. All Horizon deployments that expose the /api/v2 REST endpoints, such as the36.0.3 releases, are vulnerable. The vendor’s installation guidelines state that Horizon should run within private networks and should not be directly exposed to the Internet.
Risk and Exploitability
The vulnerability receives a CVSS score of 8.2, classifying it as high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is the web interface; an attacker must have network reach to the Horizon server to exploit the unauthenticated PATCH calls. Due to the absence of denial of monitoring services, which can have serious operational impact in a production environment.
OpenCVE Enrichment