Medium severity5.4NVD Advisory· Published Apr 6, 2026· Updated Apr 9, 2026
CVE-2026-22675
CVE-2026-22675
Description
OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitation and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.
Affected products
1- cpe:2.3:a:ocsinventory-ng:ocs_inventory_server:*:*:*:*:*:*:*:*Range: <=2.12.3
Patches
178faf2ca8b89Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3- github.com/OCSInventory-NG/OCSInventory-Server/commit/78faf2ca8b897141ba4d337d75692ab8e405bd4envdPatch
- www.vulncheck.com/advisories/ocs-inventory-ng-server-stored-xss-via-user-agentnvdThird Party AdvisoryVDB Entry
- github.com/OCSInventory-NG/OCSInventory-Server/pull/483nvdIssue Tracking
News mentions
0No linked articles in our index yet.