CVE-2026-14871: Osticket
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Affected products
- Osticket Osticket: version v1.18.3 only; version v1.17.7 only
Published 2026-07-17. Last modified 2026-07-17.