SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76177

HIGH · CVSS 7.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A Server-Side Request Forgery (SSRF) vulnerability exists in the /ocsreports/?function=tele_activate endpoint, allowing authenticated users with operator privileges to manipulate the HTTPS_SERV and FILE_SERV parameters. This flaw enables attackers to make unauthorized HTTP/HTTPS requests to external systems or internal resources, potentially exposing sensitive internal network services or cloud metadata. Organizations using OCS Inventory should prioritize addressing this vulnerability to mitigate the risk of unauthorized access to their systems.

CVE
CVE-2026-76177
Severity
HIGH
CVSS
7.1
EPSS
0.34%

Original NVD Description

Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.