CVE-2026-76177: Multiple vulnerabilities in Ocsreports for OCS Inventory NG
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=teleactivate endpoint due to insufficient validation of the HTTPSSERV and FILESERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OCS Inventory NGto a version that resolves this vulnerability.Fixed in 2.12.6
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with operator privileges can exploit it. Unauthenticated users are not identified as able to trigger the vulnerable endpoint.
What access does an attacker need to make requests through the server?
The attacker needs operator-level access and the ability to supply values for the HTTPS_SERV and FILE_SERV parameters to the /ocsreports/?function=tele_activate endpoint.
What kinds of systems could be reached through the vulnerability?
The server may be induced to make HTTP or HTTPS requests to external systems or internal resources. This may expose internal network services or cloud-service metadata resources reachable by the OCS Inventory server.