Junglewise Threat Intelligence

CVE-2026-19596: OpenNMS XML External Entity injection in XML collector

CVE-2026-19596 · Severity: medium · CVSS 5.9 · Published 2026-09-10

Executive brief

OpenNMS Meridian and Horizon are network monitoring platforms that collect and process data from monitored systems. An XML External Entity (XXE) vulnerability in their XML collector allows an attacker who controls the source of monitored XML data—such as a compromised monitored host or via network interception—to read sensitive files (including database credentials) accessible to the OpenNMS service account and trigger out-of-band network requests. This could lead to exposure of credentials and further compromise of the monitoring infrastructure.

Technical details

An XML External Entity (XXE) vulnerability exists in the XML collector component of OpenNMS Meridian and Horizon due to improper configuration of XML parsers (DocumentBuilderFactory and TransformerFactory in AbstractXmlCollectionHandler). The parser resolves external entities and external DTDs without restriction. An attacker with control over XML responses returned during collection—achievable via a compromised monitored host, man-in-the-middle network position, or similar attack vector—can craft malicious XML to read arbitrary files accessible to the OpenNMS service account (such as database credentials) or induce out-of-band HTTP/DNS requests. The fix disables external entity and DTD resolution in the affected XML factories. Patches are available in Meridian 2024.3.13, 2025.0.10, and Horizon 36.0.4.

Affected products

  • OpenNMS Meridian versions prior to 2024.3.13, 2025.0.10
  • OpenNMS Horizon versions prior to 36.0.4

Timeline

  • 2026-09-10: disclosed: CVE-2026-19596 published
  • 2026-08-21: patched: Fix merged in PR #8782 (foundation-2023 branch)

References

Related threats