CVE-2026-22200

HIGH EPSS 99.4%
Published Jan 12, 20265mo ago · Modified Jun 17, 20261w ago
8.7 CVSS 4.0
High
Find Similar
Published Jan 12, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago

Description

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.

CVSS Details

Base Score
8.7
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
99.4% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-74

Affected Products 2

VendorProductVersionRange
enhancesoftosticket*≥1.17  –  <1.17.7
enhancesoftosticket*≥1.18  –  <1.18.3

References 5

  • github.com https://github.com/osTicket/osTicket/commit/c59b067
    Patch
  • github.com https://github.com/osTicket/osTicket/releases/tag/v1.17.7
    Release Notes
  • github.com https://github.com/osTicket/osTicket/releases/tag/v1.18.3
    Release Notes
  • horizon3.ai https://horizon3.ai/attack-research/attack-blogs/ticket-to-shell-exploiting-php-filters-and-cnext-in-osticket-cve-2026-22200/
    Exploit
  • vulncheck.com https://www.vulncheck.com/advisories/osticket-pdf-export-arbitrary-file-read
    Third Party Advisory

Remediation

  • github.com https://github.com/osTicket/osTicket/commit/c59b067
    Patch