CVE-2026-28517
openDCIM OS Command Injection via Network Map Reporting
Halo Surface Signal: 3 out of 5 — possibly public-facing.
An OS command injection vulnerability exists in openDCIM's network map reporting feature. An attacker could execute arbitrary commands on the web server by altering a database configuration parameter, as the application does not validate this input before using it in a system command. This poses a risk if the openDCIM