Executive brief
osTicket is a popular open-source helpdesk ticketing system. The application generates API keys—long-lived credentials used to access and modify ticket data—using a weak cryptographic method (MD5) combined with predictable information like timestamps and IP addresses. An attacker who obtains a leaked API key hash can recover the actual key through brute-force attack, gaining unauthorized access to all tickets, the ability to create tickets as other users, and permission to trigger administrative tasks.
Technical details
The vulnerability is a use of broken cryptographic algorithms (CWE-327) and weak PRNG (CWE-338) in the API key generation function. osTicket's include/class.api.php (line 149) constructs API keys as md5(time() . $vars['ipaddr'] . md5(Misc::randCode(16))). MD5 is cryptographically broken and can be computed at billions of hashes per second on GPUs. The inputs are also predictable: Unix timestamps can be approximated from logs or ticket metadata, and client IP addresses are often observable or documented. An attacker with a leaked API key hash, approximate creation time, and the target IP can materially reduce the search space and recover the key via brute-force. No authentication is required to exploit a recovered key; admin credentials are only needed to initially generate it. As of the advisory publication, no patched version had been released. The remediation is to use a cryptographically secure PRNG (e.g., bin2hex(random_bytes(32))) instead of MD5 and remove dependency on timestamp and IP address.
Affected products
- Enhancesoft LLC osTicket <= 1.18.3
Timeline
- 2026-08-03: disclosed
- other: Unpatched as of advisory publication