Local File Inclusion in OCS Inventory

Posted date 24/07/2026
Identificador
INCIBE-2026-507
Importance
3 - Medium
Affected Resources

OCSreports 2.12.4 version.

Description

INCIBE has coordinated the disclosure of a medium-severity vulnerability affecting OCSreports from OCS Inventory, free and open-source software designed to manage the inventory of IT assets on a network. The vulnerability was discovered by Adrián Ferrer Tarí.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type: 

  • CVE-2026-16475: CVSS v4.0: 6.9 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N | CWE-98
Solution

The vulnerability has been fixed by the OCS Inventory team in the latest version.

Detail

CVE-2026-16475: local file inclusion (LFI) vulnerability in the '/ajax/teledeployoptions.php' component due to inadequate sanitisation of the 'linkedoptions' parameter prior to its use in a dynamic file inclusion operation. An unauthenticated remote attacker could exploit this vulnerability to include and access arbitrary files within the application directory, resulting in the disclosure of information about the application’s internal resources. Furthermore, the varying server responses allow attackers to enumerate system files and perform operating system fingerprinting.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-16475 Media No OCS Inventory
References list