🔐 CVE Alert

CVE-2026-76177

UNKNOWN 0.0

Multiple vulnerabilities in Ocsreports for OCS Inventory NG

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.

CWE CWE-918
Vendor ocs inventory ng
Product ocsreports
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for ocs inventory ng ocsreports

Be the first to know when new unknown vulnerabilities affecting ocs inventory ng ocsreports are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

OCS Inventory NG / Ocsreports
2.12.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng

Credits

Marc Monfort Muñoz