CVE-2026-14871: Osticket

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.

Affected products

  • Osticket Osticket: version v1.18.3 only; version v1.17.7 only

Published 2026-07-17. Last modified 2026-07-17.