HIGH 8.6 NVD

CVE-2026-76176

SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the

SQL injection vulnerability in the endpoint /ocsreports/index.php?function=admin_double due to improper processing of the values in the ID field included in the selected_grp_dupli[] parameter. An authenticated user with operator privileges can manipulate these values to alter the SQL queries executed by the application and retrieve information stored in the database.

References

Published: 2026-09-03 · Source: NVD · Feed updated: 2026-09-03
This high severity vulnerability with a CVSS score of 8.6 was published on 2026-09-03 via NVD.
vulnfeed aggregates 7805 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.