CVE-2026-19135
Last modified
CVE-2026-19135 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| The OpenNMS Group | Meridian | >= 2024.1.0, < 2024.3.12; >= 2025.0.0, < 2025.0.9 |
| The OpenNMS Group | Horizon | >= 36.0.0, < 36.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-19135?
How severe is CVE-2026-19135?
How do I fix CVE-2026-19135?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19117Under specific conditions, an attacker can register an attac…9.8
- CVE-2026-19118A time-of-check time-of-use race condition vulnerability was…7.5
- CVE-2026-1912The Citations tools plugin for WordPress is vulnerable to St…6.4
- CVE-2026-19127An issue in the billing and license activation subsystem all…6.5
- CVE-2026-1913The Gallagher Website Design plugin for WordPress is vulnera…6.4
- CVE-2026-19130A flaw was found in the provider-credential-controller compo…5.8
- CVE-2026-19136A potential command injection vulnerability was reported in …7.8
- CVE-2026-19137Use after free in WebGL in Google Chrome on Android prior to…8.3
- CVE-2026-19138Heap buffer overflow in CrashReporting in Google Chrome prio…8.3
- CVE-2026-19139Race in CredentialProvider in Google Chrome on Windows prior…7.4
- CVE-2026-1914The FuseDesk plugin for WordPress is vulnerable to Stored Cr…6.4
- CVE-2026-19140Use after free in GPU in Google Chrome prior to 151.0.7922.1…8.3
Are you affected by CVE-2026-19135?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
