Description
Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file types. This allows a user with administrator privileges to upload PHP files to a directory accessible via the web interface. If the file is subsequently processed by the server, an attacker could execute arbitrary code with the privileges of the account used by the web service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The vulnerabilities have been fixed by the OCS Inventory NG team in version 2.12.6.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 03 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file types. This allows a user with administrator privileges to upload PHP files to a directory accessible via the web interface. If the file is subsequently processed by the server, an attacker could execute arbitrary code with the privileges of the account used by the web service. | |
| Title | Multiple vulnerabilities in Ocsreports for OCS Inventory NG | |
| First Time appeared |
Ocs Inventory Ng
Ocs Inventory Ng ocsreports |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:ocs_inventory_ng:ocsreports:2.12.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Ocs Inventory Ng
Ocs Inventory Ng ocsreports |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-03T09:38:05.161Z
Reserved: 2026-08-19T10:24:12.151Z
Link: CVE-2026-76174
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-09-03T11:30:03Z
Weaknesses
-
CWE-434
Unrestricted Upload of File with Dangerous Type