CVE-2026-22675

MEDIUM

OCS Inventory NG Server Stored XSS via User-Agent

Title source: cna

Description

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitation and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.

Scores

CVSS v3 5.4
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
OCS Inventory/OCS Inventory NG Server < 2.12.3
OCS Inventory/OCS Inventory NG Server 78faf2ca8b897141ba4d337d75692ab8e405bd4e
ocsinventory-ng/ocs_inventory_server < 2.12.3
Published Apr 06, 2026
Tracked Since Apr 07, 2026