Server-Side Request Forgery Vulnerability in OCS Inventory Server by Open Computer and Software Inventory Next Generation
CVE-2026-76177

7.1HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-76177?

A server-side request forgery (SSRF) vulnerability exists within the /ocsreports/?function=tele_activate endpoint of OCS Inventory NG. Due to inadequate validation of the HTTPS_SERV and FILE_SERV parameters, an authenticated user with operator privileges can manipulate these parameters to direct the OCS Inventory server to make unauthorized HTTP/HTTPS requests. This exploitation may lead to access of internal network services or sensitive metadata from cloud resources, creating significant security risks for organizations utilizing the affected software.

Affected Version(s)

Ocsreports 2.12.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marc Monfort Muñoz
.