{"id":"CVE-2026-76177","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-76177","summary":"Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated…","details":"Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?function=tele_activate endpoint due to insufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authenticated user with operator privileges can provide arbitrary values for these parameters, causing the OCS Inventory server to make HTTP/HTTPS requests to external systems or internal resources, which could allow access to internal network services or metadata resources of cloud services.","published":"2026-09-03T13:06:08.150","modified":"2026-09-03T13:06:08.150","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T13:06:08.150"}}