CVE-2026-76176: Multiple vulnerabilities in Ocsreports for OCS Inventory NG
SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admindouble due to improper processing of the values in the ID field included in the selectedgrpdupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ocsreports for OCS Inventory NGto a version that resolves this vulnerability.Fixed in 2.12.6
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must authenticate to Ocsreports with operator privileges. The issue is exposed through the admin_double function in /ocsreports/index.php and the selected_grp_dupli[] parameter.
What can exploitation allow an attacker to access?
Successful exploitation can alter SQL queries executed by the application and retrieve information stored in the database.