CRITICAL
openDCIM <= 23.04 SQL Injection in Config::UpdateParameter
Published Feb 27, 2026
9.3
CRITICALCVSS 4.0
EPSS 1.54%
Description
openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.
Affected products
-
- Version 0StatusaffectedConstraints<=23.04
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ technical-descriptionexploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9097 Advisory
- https://github.com/Chocapikk/opendcim-exploit exploit
- https://github.com/opendcim/openDCIM/blob/4467e9c4/config.inc.php#L75-L90 Product
- https://github.com/opendcim/openDCIM/blob/4467e9c4/install.php#L420-L434 Product
- https://github.com/opendcim/openDCIM/pull/1664 issue-trackingIssue TrackingPatch
- https://github.com/opendcim/openDCIM/pull/1664/changes/8f7ab2a710086a9c8c269560793e47c577ddda09 issue-trackingIssue TrackingPatch
- https://www.vulncheck.com/advisories/opendcim-sql-injection-in-config-updateparameter third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/ | technical-descriptionexploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9097 | Advisory | |
| https://github.com/Chocapikk/opendcim-exploit | exploit | |
| https://github.com/opendcim/openDCIM/blob/4467e9c4/config.inc.php#L75-L90 | Product | |
| https://github.com/opendcim/openDCIM/blob/4467e9c4/install.php#L420-L434 | Product | |
| https://github.com/opendcim/openDCIM/pull/1664 | issue-trackingIssue TrackingPatch | |
| https://github.com/opendcim/openDCIM/pull/1664/changes/8f7ab2a710086a9c8c269560793e47c577ddda09 | issue-trackingIssue TrackingPatch | |
| https://www.vulncheck.com/advisories/opendcim-sql-injection-in-config-updateparameter | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Feb 27, 2026
Updated Jul 14, 2026
Reserved Feb 27, 2026
Link CVE-2026-28516
CISA Vulnrichment
Updated Mar 2, 2026
ENISA EUVD
EUVD-2026-9097 Assigner VulnCheck
Published Feb 27, 2026
Updated Jul 14, 2026
Exploited since n/a
Link EUVD-2026-9097