Junglewise Threat Intelligence

CVE-2026-76177: OCS Inventory Ocsreports SSRF in tele_activate endpoint

CVE-2026-76177 · Severity: info · CVSS 7.1 · Published 2026-09-03

Technologies: OCS Inventory Ocsreports.

Executive brief

OCS Inventory is an open-source asset management solution for IT infrastructure. The Ocsreports component contains a Server-Side Request Forgery vulnerability that allows authenticated operators to trick the server into making arbitrary HTTP/HTTPS requests to internal network services or cloud metadata endpoints, potentially exposing sensitive configuration data and internal service information.

Technical details

This Server-Side Request Forgery (CWE-918) vulnerability exists in the /ocsreports/?function=tele_activate endpoint where the HTTPS_SERV and FILE_SERV parameters are not properly validated. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the server to make uncontrolled HTTP/HTTPS requests to external systems or internal resources. This allows attackers to access internal network services, retrieve cloud metadata, or interact with services that trust the OCS Inventory server. The vulnerability was fixed in OCS Inventory NG version 2.12.6.

Affected products

  • OCS Inventory Ocsreports 2.12.4 and earlier

Timeline

  • 2026-09-03: disclosed
  • 2026-09-03: patched: Fixed in OCS Inventory NG version 2.12.6

References