
CVE-2026-19135: a JEXL sandbox bypass in OpenNMS's Measurements REST API lets a low-privileged user load arbitrary Java classes on the server (CVSS 5.4, CWE-470). It is a sandbox escape, not a direct injection. Fixed in Horizon 36.0.3 and Meridian 2024.3.12 / 2025.0.9. https://hol.org/blog/cve-2026-19135-opennms-jexl-measurement-sandbox-bypass
Post summary
CVE-2026-19135 is a JEXL sandbox bypass in OpenNMS allowing low‑privileged users to load arbitrary Java classes (CVSS 5.4, CWE‑470). It has been fixed in Horizon 36.0.3 and Meridian 2024.3.12/2025.0.9.


