PatchSiren

OCS Inventory NG CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL OCS Inventory NG CVE published 2026-09-03

CVE-2026-76178

A stored Cross-Site Scripting (XSS) vulnerability exists in the notification template functionality of the endpoint /ocsreports/?function=notification. An administrator can input malicious HTML content, which is stored and displayed without proper sanitization when other administrators access the template customization view. This allows JavaScript code execution within the application's security context, [truncated]

HIGH OCS Inventory NG CVE published 2026-09-03

CVE-2026-76175

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-03T13:06:07.867Z and has not been modified since then. The vulnerability is a SQL injection issue in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. An authenticated user with operator privileges can manipulate the SQL query, potentially leading to information extracti [truncated]

CRITICAL OCS Inventory NG CVE published 2026-09-03

CVE-2026-76174

The Ocsreports admin_info endpoint is vulnerable to unrestricted file uploads, allowing administrators to upload PHP files that can be executed by the server, potentially leading to arbitrary code execution with the privileges of the account used by the web service. This critical vulnerability affects administrators and security teams responsible for Ocsreports installations, who should be aware and take [truncated]