Junglewise Threat Intelligence

CVE-2026-38446: osTicket stored XSS in thread entry title

CVE-2026-38446 · Severity: medium · CVSS 6.1 · Published 2026-08-03

Technologies: Enhancesoft osTicket. Vendors: Enhancesoft.

Executive brief

osTicket is a help desk ticketing system used by organizations to manage customer support requests. A stored cross-site scripting vulnerability allows attackers to inject malicious JavaScript into ticket threads via crafted subject lines in emails or ticket replies. When staff or customers view the affected ticket, the malicious code executes in their browser, enabling attackers to steal session cookies, impersonate users, access sensitive customer data, or perform unauthorized actions on behalf of legitimate staff members.

Technical details

The vulnerability is a stored XSS (CWE-79) in osTicket 1.18.3 affecting the thread entry title field. The root cause is a missing output-encoding layer: the title is sanitized at write time via Format::sanitize() in ThreadEntry::add() (include/class.thread.php), but is rendered without Format::htmlchars() HTML escaping in three templates (include/staff/templates/thread-entry.tmpl.php, include/client/templates/thread-entry.tmpl.php, include/client/templates/thread-export.tmpl.php). An unauthenticated attacker can exploit this by sending a reply or email with a malicious subject line to the helpdesk; the payload is stored and executes when any staff or client views the ticket thread. The vulnerability requires no authentication for email-based submission and minimal authentication for web-based submission. No patch has been released as of the advisory publication date.

Affected products

  • Enhancesoft LLC osTicket 1.18.3 and earlier

Timeline

  • 2026-08-03: disclosed

References