CVE-2026-76177 HIGH

CVE-2026-76177: Multiple vulnerabilities in Ocsreports for OCS Inventory NG

Vendor Ocs Inventory Ng
Product Ocsreports
Weakness CWE-918 · SSRF
Published September 3, 2026
Last update September 3, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

What the vulnerability does

01Description

Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.

Key dates

02Disclosure timeline

September 3, 2026 CVE published

Related vulnerabilities

04Related CVE