Junglewise Threat Intelligence

CVE-2026-76174: Ocsreports unrestricted file upload in admin_info endpoint

CVE-2026-76174 · Severity: info · CVSS 7.2 · Published 2026-09-03

Technologies: Ocsreports. Vendors: Ocsreports.

Executive brief

Ocsreports is an inventory and asset management tool used by organizations to track IT resources. A flaw in the CSV upload feature allows administrators to upload arbitrary files (including executable code) to a publicly accessible directory, potentially leading to complete server compromise if those files are processed by the web server.

Technical details

The vulnerability is an unrestricted file upload flaw in the admin_info endpoint's CSV upload functionality. The application performs insufficient validation, checking only the filename provided by the client rather than verifying the actual file content or enforcing a whitelist of permitted types. An attacker with administrator privileges can upload PHP files or other executable scripts to a web-accessible directory. If the server subsequently processes or executes these files, the attacker achieves remote code execution with the privileges of the web service account. The attack requires valid admin credentials but can lead to full system compromise.

Affected products

  • Ocsreports Ocsreports

Timeline

  • 2026-09-03: disclosed

References