CVE-2026-28515

CVSS

No CVSS.

o

penDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role checks. Any authenticated user can access this functionality regardless of assigned privileges. In deployments where REMOTE_USER is set without authentication enforcement, the endpoint may be accessible without credentials. This allows unauthorized modification of application configuration.

Configurations

No configuration.

History

27 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 23:16

Updated : 2026-03-02 20:30


NVD link : CVE-2026-28515

Mitre link : CVE-2026-28515

CVE.ORG link : CVE-2026-28515


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization