PT-2026-84976 · Ocs Inventory · Ocsreports

CVE-2026-76177

·

Publicado

2026-09-03

·

Atualizado

2026-09-03

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele activate endpoint due to insufficient validation of the HTTPS SERV and FILE SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-76177

Produtos afetados

Ocsreports