High severityNVD Advisory· Published Sep 3, 2026
CVE-2026-76177
CVE-2026-76177
Description
Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.