Description
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Published: 2026-07-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

osTicket v1.18.3 and v1.17.7 contain a broken object‑level authorization flaw that enables an attacker to reference ticket objects directly. The vulnerability manifests as an insecure direct object reference within the AJAX ticket‑management subsystem and allows a user to view tickets that belong to other departments, effectively leaking confidential information. This is a direct breach of confidentiality, classified as CWE‑863.

Affected Systems

The affected product is osTicket from osTicket. The flaw exists in version 1.17.7 and 1.18.3. These releases run on Linux, macOS, and Windows platforms.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score of less than 1 percent suggests a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, based on the description, it is inferred that the attack vector is a web‑based AJAX endpoint that can be accessed by authenticated users, an attacker with access to an account can request ticket identifiers from non‑department tickets and receive sensitive data. The vulnerability requires the attacker to be logged in but does not require elevated privileges, making it potentially exploitable in environments where role‑based department segregation is not strictly enforced.

Generated by OpenCVE AI on July 31, 2026 at 00:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update osTicket to the latest release (v1.18.4 or v1.17.8 for the corresponding branch).
  • Verify that the AJAX ticket‑management endpoint returns ticket data only for tickets belonging to the requester's department.
  • Configure role‑based access controls so users cannot read tickets from other departments.

Generated by OpenCVE AI on July 31, 2026 at 00:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Title osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
First Time appeared Osticket
Osticket osticket
Weaknesses CWE-863
CPEs cpe:2.3:a:osticket:osticket:v1.17.7:*:linux:*:*:*:*:*
cpe:2.3:a:osticket:osticket:v1.17.7:*:macos:*:*:*:*:*
cpe:2.3:a:osticket:osticket:v1.17.7:*:windows:*:*:*:*:*
cpe:2.3:a:osticket:osticket:v1.18.3:*:linux:*:*:*:*:*
cpe:2.3:a:osticket:osticket:v1.18.3:*:macos:*:*:*:*:*
cpe:2.3:a:osticket:osticket:v1.18.3:*:windows:*:*:*:*:*
Vendors & Products Osticket
Osticket osticket
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Osticket Osticket
cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2026-07-17T15:28:21.159Z

Reserved: 2026-07-06T14:11:41.135Z

Link: CVE-2026-14871

cve-icon Vulnrichment

Updated: 2026-07-17T15:28:15.628Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses