CVE-2026-22675
Publication date 6 April 2026
Last updated 27 May 2026
Ubuntu priority
Cvss 3 Severity Score
Description
OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the /ocsinventory endpoint. Attackers can register rogue agents or craft requests with malicious User-Agent values that are stored without sanitization and rendered with insufficient encoding in the web console, leading to arbitrary JavaScript execution in the browsers of authenticated users viewing the statistics dashboard.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ocsinventory-server | 26.04 LTS resolute | Not in release |
| 25.10 questing |
Needs evaluation
|
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial | Ignored end of ESM support, was needs-triage |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.4 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-22675
- https://github.com/OCSInventory-NG/OCSInventory-Server/commit/78faf2ca8b897141ba4d337d75692ab8e405bd4e
- https://github.com/OCSInventory-NG/OCSInventory-Server/pull/483
- https://www.vulncheck.com/advisories/ocs-inventory-ng-server-stored-xss-via-user-agent