CVE-2026-76175
—SQL injection in OCS Inventory OCSReports save_query_list endpoint
CVE-2026-76175 is an SQL injection flaw (CWE-89) in the OCS Inventory web console (OCSReports), where the del_check parameter of the /ocsreports/?function=save_query_list endpoint is incorporated into an SQL query without parameterisation or validation. The flaw is triggered by an authenticated user with operator privileges who manipulates the del_check value. Successful manipulation lets the attacker alter the query and extract information from the underlying inventory database, consistent with the CVSS 4.0 score of 8.6 (high), which reflects high confidentiality and integrity impact under network access, low attack complexity and low privileges. Any organisation running the affected OCSReports interface with operator-level accounts is potentially affected; the source data does not specify affected versions or a fixed release. There is no public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.3% (percentile 26), indicating no known exploitation at this time.
What to do: Because no fixed version is listed, track the OCS Inventory project and the INCIBE advisory (CNA: [email protected]) and upgrade as soon as a patched release is announced. In the interim, restrict operator-level accounts to trusted staff, limit network access to the /ocsreports console, apply WAF/IPS rules that flag SQL metacharacters in the del_check parameter, and review web logs for anomalous requests to /ocsreports/?function=save_query_list.
| OCS Inventory (inferred from the ocsreports endpoint; coordinated by INCIBE) OCS Inventory web console (OCSReports) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection vulnerability in the del_check parameter of the /ocsreports/?function=save_query_list endpoint. Input provided by an authenticated user with operator privileges is incorporated into an SQL query without proper parameterisation or validation, allowing the query to be manipulated and information to be extracted from the database using SQL injection techniques.
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.