SQL Injection Vulnerability in OCS Inventory NG by OCS Reports
CVE-2026-76176
8.6HIGH
What is CVE-2026-76176?
An SQL injection vulnerability found in OCS Inventory NG allows an authenticated user with operator privileges to manipulate ID field values in the selected_grp_dupli[] parameter of the /ocsreports/index.php?function=admin_double endpoint. This exploitation can enable attackers to craft malicious SQL queries, potentially leading to unauthorized access to sensitive information stored in the application's database.
Affected Version(s)
Ocsreports 2.12.6
