Local File Inclusion in OCS Inventory
OCSreports 2.12.4 version.
INCIBE has coordinated the disclosure of a medium-severity vulnerability affecting OCSreports from OCS Inventory, free and open-source software designed to manage the inventory of IT assets on a network. The vulnerability was discovered by Adrián Ferrer Tarí.
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:
- CVE-2026-16475: CVSS v4.0: 6.9 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N | CWE-98
The vulnerability has been fixed by the OCS Inventory team in the latest version.
CVE-2026-16475: local file inclusion (LFI) vulnerability in the '/ajax/teledeployoptions.php' component due to inadequate sanitisation of the 'linkedoptions' parameter prior to its use in a dynamic file inclusion operation. An unauthenticated remote attacker could exploit this vulnerability to include and access arbitrary files within the application directory, resulting in the disclosure of information about the application’s internal resources. Furthermore, the varying server responses allow attackers to enumerate system files and perform operating system fingerprinting.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-16475 | Media | No | OCS Inventory |



