CVE-2026-22200 is an arbitrary file read vulnerability affecting Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7. A remote attacker can exploit this by submitting a crafted ticket containing PHP filter expressions in rich-text HTML, which are then processed during PDF export to embed server filesystem contents as bitmap images. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a high impact on confidentiality with low attack complexity and no user interaction required, potentially leading to disclosure of sensitive local files. While not listed in CISA's KEV catalog, Nuclei templates exist for this vulnerability, and it has garnered significant community discussion, though no active exploitation or Metasploit/ExploitDB entries are currently reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.17, < 1.17.7CPE matchmatch criteria | cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:* | ||
>= 1.18, < 1.18.3CPE matchmatch criteria | cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:* | ||
>= 1.17.0, < 1.17.7CPE match | cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:* | ||
>= 1.18.0, < 1.18.3CPE match | cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.