CVE-2026-19135Disclosure

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-470

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-13: 3PoC Mentioned / Linked · 2026-08-13: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 308-13
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • HOL@HashgraphOnline
    Patch

    CVE-2026-19135: a JEXL sandbox bypass in OpenNMS's Measurements REST API lets a low-privileged user load arbitrary Java classes on the server (CVSS 5.4, CWE-470). It is a sandbox escape, not a direct injection. Fixed in Horizon 36.0.3 and Meridian 2024.3.12 / 2025.0.9. https://hol.org/blog/cve-2026-19135-opennms-jexl-measurement-sandbox-bypass

    Post summary

    CVE-2026-19135 is a JEXL sandbox bypass in OpenNMS allowing low‑privileged users to load arbitrary Java classes (CVSS 5.4, CWE‑470). It has been fixed in Horizon 36.0.3 and Meridian 2024.3.12/2025.0.9.

    01061904
    19.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19135 A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to t… https://www.cve.org/CVERecord?id=CVE-2026-19135 ----- Traducción: CVE-2026-19135 Exi… https://infoflow.cloud`

    Post summary

    CVE-2026-19135 describes a low‑privileged authenticated user bypass of a JEXL expression sandbox in OpenNMS Meridian and Horizon; no PoC, tool, exploitation report, or patch is referenced.

    0000027
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19135 A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to t… https://www.cve.org/CVERecord?id=CVE-2026-19135

    Post summary

    The note announces a sandbox bypass in OpenNMS Meridian and Horizon that lets low‑privileged authenticated users submit crafted JEXL expressions; no exploitation, PoC, or patch details are provided.

    00000823
    57.9K followersView on X

Explore more