PT-2026-22425 · Opendcim · Opendcim

Valentin Lobstein

·

Published

2026-02-27

·

Updated

2026-05-14

·

CVE-2026-28515

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions openDCIM versions 23.04 through commit 4467e9c4
Description The software contains a missing authorization issue in the install.php and container-install.php files. The installer and upgrade handler expose LDAP configuration functionality without proper application role checks. Any authenticated user can access this functionality, regardless of assigned privileges. If the REMOTE USER variable is set without authentication enforcement, the endpoint may be accessible without credentials, allowing unauthorized modification of application configuration.
Recommendations Apply updates to versions beyond commit 4467e9c4. Ensure proper authentication enforcement is in place when using the REMOTE USER variable. Restrict access to the install.php and container-install.php files to authorized personnel only.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-28515

Affected Products

Opendcim