PT-2026-84976 · Ocs Inventory · Ocsreports
CVE-2026-76177
·
Published
2026-09-03
·
Updated
2026-09-03
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N |
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele activate endpoint due to insufficient validation of the HTTPS SERV and FILE SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ocsreports