Logic Vulnerability in osTicket Password Reset Process
CVE-2026-18363

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-18363?

A logic vulnerability has been identified in osTicket's password reset token validation routine. In versions prior to v1.17.8 and v1.18.4, weaknesses in the expiry check mechanism allow attackers to exploit valid password reset tokens. The application fails to enforce a proper expiry validation when the timestamp lookup succeeds, potentially enabling unauthorized users to reset passwords and gain access to affected accounts. Users are encouraged to update to the latest version to mitigate this vulnerability and enhance account security.

Affected Version(s)

osTicket 0 < 1.17.8

osTicket 0 < 1.18.4

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ismael de Frutos DĂ­az
.