Ad

CVE-2026-22675

MEDIUM CVSS 4.0: 5.1 EPSS 0.06%
Updated Apr 09, 2026
Ocsinventory-Ng
Parameter Value
CVSS 5.1 (MEDIUM)
Affected Versions before 2.12.3
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Ocsinventory-Ng
Public PoC No

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitation and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Ocsinventory-Ng Ocs_Inventory_Server
cpe:2.3:a:ocsinventory-ng:ocs_inventory_server:*:*:*:*:*:*:*:*
<= 2.12.3