CVE-2026-76178

NameCVE-2026-76178
DescriptionA stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper sanitisation when other administrators access the template customisation view, allowing JavaScript code to be executed within the application’s security context and potentially compromising the sessions of other users with administrative privileges.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ocsinventory-server (PTS)bookworm2.8.1+dfsg1+~2.11.1-1vulnerable
sid2.8.1+dfsg1+~2.11.1-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ocsinventory-serversource(unstable)(unfixed)

Notes

https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-ocsreports-ocs-inventory-ng

Search for package or bug name: Reporting problems