CVE-2026-22675
MEDIUMOCS Inventory NG Server Stored XSS via User-Agent
Title source: cnaDescription
OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitation and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.
Scores
CVSS v3
5.4
EPSS
0.0004
EPSS Percentile
12.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (3)
OCS Inventory/OCS Inventory NG Server
< 2.12.3
OCS Inventory/OCS Inventory NG Server
78faf2ca8b897141ba4d337d75692ab8e405bd4e
ocsinventory-ng/ocs_inventory_server
< 2.12.3
Published
Apr 06, 2026
Tracked Since
Apr 07, 2026