๐Ÿ” CVE Alert

CVE-2026-22200

UNKNOWN 0.0

osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.

CWE CWE-74
Vendor enhancesoft
Product osticket
Published Jan 12, 2026
Last Updated Mar 23, 2026
Stay Ahead of the Next One

Get instant alerts for enhancesoft osticket

Be the first to know when new unknown vulnerabilities affecting enhancesoft osticket are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Enhancesoft / osTicket
1.18.0 < 1.18.3 1.17.0 < 1.17.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/osTicket/osTicket/releases/tag/v1.18.3 github.com: https://github.com/osTicket/osTicket/releases/tag/v1.17.7 github.com: https://github.com/osTicket/osTicket/commit/c59b067 horizon3.ai: https://horizon3.ai/attack-research/attack-blogs/ticket-to-shell-exploiting-php-filters-and-cnext-in-osticket-cve-2026-22200/ vulncheck.com: https://www.vulncheck.com/advisories/osticket-pdf-export-arbitrary-file-read

Credits

Naveen Sunkavally, Horizon3.ai