Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-76174: Ocsreports admin upload can run malicious scripts
CVE-2026-76174 · published today
Summary
The Ocsreports reporting tool lets administrators upload CSV files, but it only checks the file name, not the actual content. This means a malicious script could be placed on the web server and run with the web service’s rights. Admins should update the software or restrict file uploads to trusted formats and locations.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ocs inventory ng | ocsreports | 2.12.6 |
Original advisory text
Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, w...
Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file types. This allows a user with administrator privileges to upload PHP files to a directory accessible via the web interface. If the file is subsequently processed by the server, an attacker could execute arbitrary code with the privileges of the account used by the web service.
Severity
9.4
Critical
Type
CWE-434Unrestricted File Upload
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta