SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database.
Advisories
No advisories yet.
Fixes
Solution
The vulnerabilities have been fixed by the OCS Inventory NG team in version 2.12.6.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database. | |
| Title | Multiple vulnerabilities in Ocsreports for OCS Inventory NG | |
| First Time appeared |
Ocs Inventory Ng
Ocs Inventory Ng ocsreports |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:ocs_inventory_ng:ocsreports:2.12.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Ocs Inventory Ng
Ocs Inventory Ng ocsreports |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-03T09:47:21.324Z
Reserved: 2026-08-19T10:24:15.287Z
Link: CVE-2026-76176
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses