CVE-2026-28516
Last modified
CVE-2026-28516 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitation. An authenticated user can execute arbitrary SQL statements against the underlying database.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opendcim | Opendcim | 23.04 |
References
- https://chocapikk.com/posts/2026/opendcim-sqli-to-rce/Exploit, Third Party Advisory
- https://github.com/opendcim/openDCIM/pull/1664Issue Tracking, Patch
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-28516?
How severe is CVE-2026-28516?
How do I fix CVE-2026-28516?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-28510eLabFTW is an open source electronic lab notebook. In elabft…5.9
- CVE-2026-28511eLabFTW is an open source electronic lab notebook. Prior to …4.3
- CVE-2026-28512Pocket ID is an OIDC provider that allows users to authentic…6.1
- CVE-2026-28513Pocket ID is an OIDC provider that allows users to authentic…7.1
- CVE-2026-28514Rocket.Chat is an open-source, secure, fully customizable co…9.8
- CVE-2026-28515openDCIM version 23.04, through commit 4467e9c4, contains a …8.8
- CVE-2026-28517openDCIM version 23.04, through commit 4467e9c4, contains an…9.8
- CVE-2026-28518OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76…8.4
- CVE-2026-28519arduino-TuyaOpen before version 1.2.1 contains a heap-based …8.8
- CVE-2026-2852A vulnerability was identified in yeqifu warehouse up to aaf…6.3
- CVE-2026-28520arduino-TuyaOpen before version 1.2.1 contains a single-byte…8.6
- CVE-2026-28521arduino-TuyaOpen before version 1.2.1 contains an out-of-bou…7.7
Are you affected by CVE-2026-28516?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
