CVE-2026-28517Exploit(opendcim / opendcim)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch opendcim opendcim systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it directly to exec() without validation or sanitization. If an attacker can modify the fac_Config.dot value, arbitrary commands may be executed in the context of the web server process.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opendcim

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-28); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
opendcim

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-27: 1Mentions · 2026-02-28: 2Mentions · 2026-03-04: 1Mentions · 2026-05-14: 1Mentions · 2026-05-18: 1PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-04: 1Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-03-04: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-18: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-04: 102-2702-2803-0405-1405-18
Signal classification3 categories
Exploit
233.3%
Disclosure
233.3%
Active Exploitation
233.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-271
Exploit1
2026-02-282
Disclosure2
2026-03-041
Exploit1
2026-05-141
Active Exploitation1
2026-05-181
Active Exploitation1
Full discourse6 posts
  • Chocapikk 🤘🏻@Chocapikk_
    Exploit

    3 new CVEs published today: CVE-2026-28515 - Missing Authorization CVE-2026-28516 - SQL Injection CVE-2026-28517 - OS Command Injection Chained together: unauthenticated RCE on openDCIM Docker deployments. https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ Exploit built on @VulnCheckAI's go-exploit: https://github.com/Chocapikk/opendcim-exploit

    Post summary

    Three new CVEs in openDCIM allow unauthenticated RCE, with a functional exploit already available on GitHub.

    5410161768.3K
    3.9K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    🐚 Our Canaries detected first-time exploitation of openDCIM CVE-2026-28515 + CVE-2026-28517 today. Threat activity comes from a single Chinese IP, conducts automated Vulnhuntr recon before dropping PHP webshells. OpenDCIM chain discovered by VulnCheck researcher @Chocapikk_ 🎉 https://t.co/RTVPp1ChXX

    Post summary

    The tweet reports a first-time exploitation of openDCIM CVE-2026-28515 and CVE-2026-28517, with an attacker dropping PHP webshells, but does not provide a PoC, exploit tool details, or patch information.

    01503083.2K
    3.6K followersView on X
  • dbugs@ptdbugs
    Exploit

    openDCIM: from SQL Injection to RCE via config poisoning A vulnerability chain was discovered in the open-source tool "openDCIM" (CVE-2026-28515 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22425), CVE-2026-28516 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22426) and CVE-2026-28517 -> (https://dbugs.ptsecurity.com/vulnerability/PT-2026-22427)), allowing an attacker to achieve Remote Code Execution (RCE) on the server. The vulnerabilities are rated 9.3 on the CVSS v4.0 scale. The root causes include missing authorization checks in "install.php", an SQL injection flaw in configuration parameter updates, and unsafe command handling within the "exec()" function via the "dot" field. As a result, arbitrary commands can be injected via HTTP requests and executed with "www-data" privileges. In Docker-based deployments, the entire process can be exploited without authentication. 📎 Article: https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ 🛠 Tool: https://github.com/Chocapikk/opendcim-exploit #dbugs_attacks

    Post summary

    The report outlines a high‑severity CVE chain in openDCIM that leads to RCE via SQL injection and command execution, provides a GitHub exploit for demonstration, yet does not confirm active exploitation or patches.

    00011147
    551 followersView on X
  • Michael Martino@battista212
    Active Exploitation

    openDCIM exploitation campaign active—attackers using AI to find targets and drop PHP webshells via CVE-2026-28515 and CVE-2026-28517. All activity from one Chinese IP. Verify February patches applied and remove installation artifacts.

    Post summary

    The text reports an active openDCIM exploitation campaign using CVE‑2026‑28515 and CVE‑2026‑28517 to drop PHP webshells, and advises verifying February patches and removing installation artifacts.

    1000042
    243 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28517 openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configu… https://www.cve.org/CVERecord?id=CVE-2026-28517

    Post summary

    The text announces an OS command injection vulnerability in openDCIM 23.04, specifically in report_network_map.php, and references the CVE record for further details.

    00000112
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28517 OS Command Injection in openDCIM 23.04 via Unvalidated 'dot' Para... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28517 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-28517, an OS command injection flaw in openDCIM 23.04, but provides no PoC, exploit code, or patch details.

    0000062
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopendcimopendcim23.04--

Explore more