PatchSiren cyber security CVE debrief
CVE-2026-14871 osTicket CVE debrief
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) vulnerability leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem. This issue allows attackers to access sensitive information or perform unauthorized actions on tickets. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Organizations using these versions should prioritize patching to prevent potential exploitation.
- Vendor
- osTicket
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-17
- Original CVE updated
- 2026-07-17
- Advisory published
- 2026-07-17
- Advisory updated
- 2026-07-17
Who should care
Organizations using osTicket versions v1.18.3 and v1.17.7 should prioritize patching this vulnerability to prevent potential exploitation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure the security of their systems.
Technical summary
The CVE-2026-14871 vulnerability is caused by a Broken Object Level Authorization (BOLA) issue in the AJAX ticket-management subsystem of osTicket versions v1.18.3 and v1.17.7. This allows an attacker to access or manipulate ticket information without proper authorization. The vulnerability has a CVSS score of 7.1, indicating a high severity level. The issue can be mitigated by applying patches or updates provided by the vendor.
Defensive priority
High
Recommended defensive actions
- Apply patches or updates provided by the vendor to address the BOLA vulnerability
- Implement additional access controls and monitoring to detect potential exploitation attempts
- Conduct thorough inventory checks to identify affected systems
- Consider compensating controls such as Web Application Firewalls (WAFs) to help mitigate the vulnerability
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-17T16:17:13.580Z and was last modified on 2026-07-17T18:10:00.977Z. The NVD entry is currently Awaiting Analysis. This information is based on the NVD entry and the CVE record. The affected product, osTicket, has versions v1.18.3 and v1.17.7 that are vulnerable to this issue. The CVE record and NVD entry provide further details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14871 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14871
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14871 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14871
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://fluidattacks.com/advisories/kyokai
-
Source reference
Unverified legacy reference
URL: https://github.com/osTicket/osTicket/
-
Source reference
Unverified legacy reference
URL: https://github.com/osTicket/osTicket/releases/tag/v1.17.8
-
Source reference
Unverified legacy reference
URL: https://github.com/osTicket/osTicket/releases/tag/v1.18.4
-
Source reference
Unverified legacy reference
URL: https://medium.com/p/1abb8be847e6
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.