
3 new CVEs published today: CVE-2026-28515 - Missing Authorization CVE-2026-28516 - SQL Injection CVE-2026-28517 - OS Command Injection Chained together: unauthenticated RCE on openDCIM Docker deployments. https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ Exploit built on @VulnCheckAI's go-exploit: https://github.com/Chocapikk/opendcim-exploit
Post summary
Three newly disclosed CVEs enable a chained unauthenticated RCE on openDCIM Docker deployments; exploit code is publicly available on GitHub, but no patch or evidence of active exploitation is mentioned.



