CVE-2026-28516Exploit(opendcim / opendcim)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for opendcim opendcim systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opendcim

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-28); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
opendcim

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-27: 1Mentions · 2026-02-28: 2Mentions · 2026-03-04: 1PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-04: 1Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-03-04: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-04: 102-2702-2803-04
Signal classification2 categories
Exploit
250.0%
Disclosure
250.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-271
Exploit1
2026-02-282
Disclosure2
2026-03-041
Exploit1
Full discourse4 posts
  • Chocapikk 🤘🏻@Chocapikk_
    Exploit

    3 new CVEs published today: CVE-2026-28515 - Missing Authorization CVE-2026-28516 - SQL Injection CVE-2026-28517 - OS Command Injection Chained together: unauthenticated RCE on openDCIM Docker deployments. https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ Exploit built on @VulnCheckAI's go-exploit: https://github.com/Chocapikk/opendcim-exploit

    Post summary

    Three newly disclosed CVEs enable a chained unauthenticated RCE on openDCIM Docker deployments; exploit code is publicly available on GitHub, but no patch or evidence of active exploitation is mentioned.

    5410161768.3K
    3.9K followersView on X
  • dbugs@ptdbugs
    Exploit

    openDCIM: from SQL Injection to RCE via config poisoning A vulnerability chain was discovered in the open-source tool "openDCIM" (CVE-2026-28515 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22425), CVE-2026-28516 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22426) and CVE-2026-28517 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22427)), allowing an attacker to achieve Remote Code Execution (RCE) on the server. The vulnerabilities are rated 9.3 on the CVSS v4.0 scale. The root causes include missing authorization checks in "install.php", an SQL injection flaw in configuration parameter updates, and unsafe command handling within the "exec()" function via the "dot" field. As a result, arbitrary commands can be injected via HTTP requests and executed with "www-data" privileges. In Docker-based deployments, the entire process can be exploited without authentication. 📎 Article: https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ 🛠 Tool: https://github.com/Chocapikk/opendcim-exploit #dbugs_attacks

    Post summary

    The post discloses an openDCIM vulnerability chain leading to RCE, provides technical details, and supplies a functional exploit script, but does not report active wild exploitation or vendor patches.

    00011147
    551 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28516 openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers… https://www.cve.org/CVERecord?id=CVE-2026-28516

    Post summary

    The text announces a SQL injection vulnerability in openDCIM 23.04, detailing the affected function and commit, but does not provide PoC, exploit, or patch information.

    00000110
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28516 SQL Injection in openDCIM 23.04 via Unsanitized Config Parameter Update https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28516

    Post summary

    The post announces a SQL injection vulnerability (CVE-2026-28516) in openDCIM 23.04 caused by an unsanitized configuration parameter, without any PoC, exploit, patch, or active exploitation details.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopendcimopendcim23.04--

Explore more