Junglewise Threat Intelligence

CVE-2026-22675: OCS Inventory NG Server stored XSS via User-Agent header

CVE-2026-22675 · Severity: medium · CVSS 5.4 · Published 2026-04-06

Executive brief

OCS Inventory NG Server, a tool used for IT asset management and inventory tracking, is vulnerable to a security flaw where an attacker can inject malicious scripts into the system. By sending a specially crafted web request, an attacker can store a malicious script that will run in the browser of an administrator viewing the management console. This could allow an attacker to steal session information or perform unauthorized actions on behalf of the administrator.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in OCS Inventory NG Server versions 2.12.3 and prior. The vulnerability is located in the /ocsinventory endpoint, which fails to properly sanitize the User-Agent HTTP header before storing it in the database. When an administrator views the statistics dashboard in the web console, the unsanitized User-Agent string is rendered with insufficient encoding, leading to arbitrary JavaScript execution in the context of the authenticated user's session. Attackers can exploit this by registering rogue agents or sending direct HTTP requests with malicious payloads. A fix has been identified in commit 78faf2c which implements character filtering for the User-Agent header.

Affected products

  • OCS Inventory NG OCS Inventory NG Server <= 2.12.3

Timeline

  • 2026-02-23: other: Initial pull request for fix created
  • 2026-03-23: patched: Fix merged into master branch
  • 2026-04-06: disclosed: Vulnerability disclosed by VulnCheck
  • 2026-04-06: advisory: NVD published the CVE record

References