osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) vulnerability leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem. This issue allows attackers to access sensitive information or perform unauthorized actions on tickets. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Organizations using these versi [truncated]
CVE-2026-8194 is a low-severity cross-site request forgery issue reported in osTicket versions up to 1.18.3. The source record says the problem is in include/class.dispatcher.php within the Dispatcher component and can be triggered by manipulating the _method argument. The same source also notes that the issue was publicly disclosed and that the project was notified early via a pull request, but had not r [truncated]