Executive brief
osTicket is an open-source customer support ticket system used by organizations to manage help desk requests. A security flaw in the ticket-management system allows an authenticated user to view sensitive ticket data belonging to other departments that they should not have access to. This could lead to the unauthorized disclosure of private customer information or internal support details.
Technical details
A Broken Object Level Authorization (BOLA) vulnerability exists in the AJAX ticket-management subsystem of osTicket. The flaw is categorized as an Insecure Direct Object Reference (IDOR) resulting from incorrect authorization (CWE-863). An attacker with low-privileged authenticated access can exploit this by manipulating object identifiers in network requests to view ticket fields and data across different departments. This allows for cross-department data disclosure. The vulnerability is addressed in versions v1.17.8 and v1.18.4.
Affected products
- osTicket osTicket v1.18.3, v1.17.7
Timeline
- 2026-06-17: patched: Versions v1.17.8 and v1.18.4 released.
- 2026-07-17: disclosed: Vulnerability details published by Fluid Attacks.
- 2026-07-17: advisory: CVE-2026-14871 published to NVD.