CVE-2026-28515Active Exploitation(opendcim / opendcim)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch opendcim opendcim systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role checks. Any authenticated user can access this functionality regardless of assigned privileges. In deployments where REMOTE_USER is set without authentication enforcement, the endpoint may be accessible without credentials. This allows unauthorized modification of application configuration.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opendcim

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-02-28); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
opendcim

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-02-27: 1Mentions · 2026-02-28: 2Mentions · 2026-03-01: 1Mentions · 2026-03-04: 1Mentions · 2026-05-14: 1Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-04: 1Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-03-04: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-05-19: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-04: 1Technical Details · 2026-05-19: 102-2702-2803-0103-0405-1405-1805-19
Signal classification4 categories
Active Exploitation
337.5%
Exploit
225.0%
General
225.0%
Disclosure
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-271
Exploit1
2026-02-282
Disclosure1General1
2026-03-011
General1
2026-03-041
Exploit1
2026-05-141
Active Exploitation1
2026-05-181
Active Exploitation1
2026-05-191
Active Exploitation1
Full discourse8 posts
  • Chocapikk 🤘🏻@Chocapikk_
    Exploit

    3 new CVEs published today: CVE-2026-28515 - Missing Authorization CVE-2026-28516 - SQL Injection CVE-2026-28517 - OS Command Injection Chained together: unauthenticated RCE on openDCIM Docker deployments. https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ Exploit built on @VulnCheckAI's go-exploit: https://github.com/Chocapikk/opendcim-exploit

    Post summary

    The post announces three new CVEs for openDCIM and provides a PoC and functional exploit chain leading to an unauthenticated RCE, but does not mention patches or evidence of active exploitation.

    5410161768.3K
    3.9K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    🐚 Our Canaries detected first-time exploitation of openDCIM CVE-2026-28515 + CVE-2026-28517 today. Threat activity comes from a single Chinese IP, conducts automated Vulnhuntr recon before dropping PHP webshells. OpenDCIM chain discovered by VulnCheck researcher @Chocapikk_ 🎉 https://t.co/RTVPp1ChXX

    Post summary

    Canaries detected first‑time exploitation of openDCIM CVE‑2026‑28515 and CVE‑2026‑28517 with PHP webshells dropped by a single Chinese IP, indicating active attacks.

    01503083.2K
    3.6K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Hackers weaponize openDCIM flaws CVE-2026-28515, 28516, and 28517 for sub-second unauthenticated RCE. Secure your data center infrastructure now! https://securityexpress.info/data-centers-exposed-open-source-opendcim-exploit-chain-actively-weaponized-for-in-the-wild-takeovers/ https://t.co/yMwoPSDObG

    Post summary

    Hackers are actively exploiting three openDCIM CVEs (CVE‑2026‑28515/28516/28517) via sub‑second unauthenticated remote code execution, highlighting an urgent need for data center security measures.

    020102669
    12.5K followersView on X
  • dbugs@ptdbugs
    Exploit

    openDCIM: from SQL Injection to RCE via config poisoning A vulnerability chain was discovered in the open-source tool "openDCIM" (CVE-2026-28515 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22425), CVE-2026-28516 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22426) and CVE-2026-28517 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22427)), allowing an attacker to achieve Remote Code Execution (RCE) on the server. The vulnerabilities are rated 9.3 on the CVSS v4.0 scale. The root causes include missing authorization checks in "install.php", an SQL injection flaw in configuration parameter updates, and unsafe command handling within the "exec()" function via the "dot" field. As a result, arbitrary commands can be injected via HTTP requests and executed with "www-data" privileges. In Docker-based deployments, the entire process can be exploited without authentication. 📎 Article: https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ 🛠 Tool: https://github.com/Chocapikk/opendcim-exploit #dbugs_attacks

    Post summary

    Researchers revealed a chain of CVEs in OpenDCIM that lead from SQL injection to RCE, provided detailed technical info and a publicly available exploit tool, but did not report any active exploitation or patches.

    00011147
    551 followersView on X
  • Michael Martino@battista212
    Active Exploitation

    openDCIM exploitation campaign active—attackers using AI to find targets and drop PHP webshells via CVE-2026-28515 and CVE-2026-28517. All activity from one Chinese IP. Verify February patches applied and remove installation artifacts.

    Post summary

    The post reports an ongoing exploitation campaign targeting openDCIM using CVE-2026-28515 and CVE-2026-28517, advises verifying February patches, and notes a single source IP.

    1000042
    243 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-0625 2 - CVE-2016-4655 3 - CVE-2025-27363 4 - CVE-2026-28515 5 - CVE-2026-21509 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five CVE identifiers as trending, without providing any additional context, technical details, or actionable information.

    00010267
    1.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28515 openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade ha… https://www.cve.org/CVERecord?id=CVE-2026-28515

    Post summary

    The CVE-2026-28515 vulnerability in openDCIM 23.04 is a missing authorization flaw in installer scripts, as disclosed in the CVE record.

    00000121
    56.6K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-35202 2 - CVE-2019-12735 3 - CVE-2025-40552 4 - CVE-2026-21253 5 - CVE-2026-28515 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without providing any details on exploitation, mitigation, or technical specifics.

    00000342
    1.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopendcimopendcim23.04--

Explore more