Logic Vulnerability in osTicket Password Reset Process
CVE-2026-18363
9.1CRITICAL
What is CVE-2026-18363?
A logic vulnerability has been identified in osTicket's password reset token validation routine. In versions prior to v1.17.8 and v1.18.4, weaknesses in the expiry check mechanism allow attackers to exploit valid password reset tokens. The application fails to enforce a proper expiry validation when the timestamp lookup succeeds, potentially enabling unauthorized users to reset passwords and gain access to affected accounts. Users are encouraged to update to the latest version to mitigate this vulnerability and enhance account security.
Affected Version(s)
osTicket 0 < 1.17.8
osTicket 0 < 1.18.4
