PatchSiren

osTicket CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH osTicket CVE published 2026-07-17

CVE-2026-14871

osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) vulnerability leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem. This issue allows attackers to access sensitive information or perform unauthorized actions on tickets. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Organizations using these versi [truncated]

LOW osTicket CVE published 2026-05-09

CVE-2026-8194

CVE-2026-8194 is a low-severity cross-site request forgery issue reported in osTicket versions up to 1.18.3. The source record says the problem is in include/class.dispatcher.php within the Dispatcher component and can be triggered by manipulating the _method argument. The same source also notes that the issue was publicly disclosed and that the project was notified early via a pull request, but had not r [truncated]