CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-28517

Critical · CVSS 9.8

openDCIM — OS Command Injection (CWE-78)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-78

Description

openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it directly to exec() without validation or sanitization. If an attacker can modify the fac_Config.dot value, arbitrary commands may be executed in the context of the web server process.

Search profile — drives PoC discovery

Symbols report_network_map.phpfac_Config.dotexec()dotfac_Config4467e9c4
Keywords CVE-2026-28517openDCIMOS command injectionreport_network_map.phpfac_Config.dotexecopendcim-exploitSQLi to RCEopenDCIM 23.04Chocapikk
Versions: 23.04 through commit 4467e9c4

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z