Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
CVE-2026-14871
Description
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/osTicket/osTicket/releases/tag/v1.17.8mitrepatch
- github.com/osTicket/osTicket/releases/tag/v1.18.4mitrepatch
- fluidattacks.com/advisories/kyokaimitrethird-party-advisory
- medium.com/p/1abb8be847e6mitrethird-party-advisory
News mentions
0No linked articles in our index yet.