NONE · 0

CVE-2026-76178

A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input maliciou...

Vulnerability Description

A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper sanitisation when other administrators access the template customisation view, allowing JavaScript code to be executed within the application’s security context and potentially compromising the sessions of other users with administrative privileges.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-76178?

CVE-2026-76178 is a documented vulnerability. A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input maliciou...

How severe is CVE-2026-76178?

CVSS scoring is not yet available for CVE-2026-76178. Check NVD for updates.

Is there a patch for CVE-2026-76178?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.