Description
SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The vulnerabilities have been fixed by the OCS Inventory NG team in version 2.12.6.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 03 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database. | |
| Title | Multiple vulnerabilities in Ocsreports for OCS Inventory NG | |
| First Time appeared |
Ocs Inventory Ng
Ocs Inventory Ng ocsreports |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:ocs_inventory_ng:ocsreports:2.12.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Ocs Inventory Ng
Ocs Inventory Ng ocsreports |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-03T12:48:56.991Z
Reserved: 2026-08-19T10:24:15.287Z
Link: CVE-2026-76176
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-09-03T12:15:03Z
Weaknesses