PT-2026-84976 · Ocs Inventory · Ocsreports

CVE-2026-76177

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele activate endpoint due to insufficient validation of the HTTPS SERV and FILE SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76177

Affected Products

Ocsreports