๐Ÿ” CVE Alert

CVE-2026-28515

UNKNOWN 0.0

openDCIM <= 23.04 Missing Authorization in install.php

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role checks. Any authenticated user can access this functionality regardless of assigned privileges. In deployments where REMOTE_USER is set without authentication enforcement, the endpoint may be accessible without credentials. This allows unauthorized modification of application configuration.

CWE CWE-862
Vendor opendcim
Product opendcim
Published Feb 27, 2026
Last Updated Mar 2, 2026
Stay Ahead of the Next One

Get instant alerts for opendcim opendcim

Be the first to know when new unknown vulnerabilities affecting opendcim opendcim are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

openDCIM / openDCIM
0 โ‰ค 23.04

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
chocapikk.com: https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ github.com: https://github.com/Chocapikk/opendcim-exploit github.com: https://github.com/opendcim/openDCIM/pull/1664 github.com: https://github.com/opendcim/openDCIM/pull/1664/changes/8f7ab2a710086a9c8c269560793e47c577ddda09 github.com: https://github.com/opendcim/openDCIM/blob/4467e9c4/install.php#L293 github.com: https://github.com/opendcim/openDCIM/blob/4467e9c4/install.php#L420-L434 github.com: https://github.com/opendcim/openDCIM/blob/4467e9c4/container-install.php#L421-L435 vulncheck.com: https://www.vulncheck.com/advisories/opendcim-missing-authorization-in-install-php

Credits

Valentin Lobstein (Chocapikk)