PT-2026-22425 · Opendcim · Opendcim
Valentin Lobstein
·
Published
2026-02-27
·
Updated
2026-05-14
·
CVE-2026-28515
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openDCIM versions 23.04 through commit 4467e9c4
Description
The software contains a missing authorization issue in the
install.php and container-install.php files. The installer and upgrade handler expose LDAP configuration functionality without proper application role checks. Any authenticated user can access this functionality, regardless of assigned privileges. If the REMOTE USER variable is set without authentication enforcement, the endpoint may be accessible without credentials, allowing unauthorized modification of application configuration.Recommendations
Apply updates to versions beyond commit 4467e9c4.
Ensure proper authentication enforcement is in place when using the
REMOTE USER variable.
Restrict access to the install.php and container-install.php files to authorized personnel only.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opendcim