AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T19:16:46.917Z and has not been modified since then. The osTicket 1.18.3 application generates API keys using a predictable construction based on MD5 hashing. This approach, combined with the use of predictable inputs like the current timestamp and client IP address, significantly reduces the entr [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T19:16:46.793Z and has not been modified since then. A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple [truncated]
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) vulnerability leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem. This issue allows attackers to access sensitive information or perform unauthorized actions on tickets. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Organizations using these versi [truncated]
CVE-2026-8194 is a low-severity cross-site request forgery issue reported in osTicket versions up to 1.18.3. The source record says the problem is in include/class.dispatcher.php within the Dispatcher component and can be triggered by manipulating the _method argument. The same source also notes that the issue was publicly disclosed and that the project was notified early via a pull request, but had not r [truncated]