Junglewise Threat Intelligence

CVE-2026-38447: osTicket weak API key generation with MD5 and predictable inputs

CVE-2026-38447 · Severity: critical · CVSS 9.8 · Published 2026-08-03

Technologies: Enhancesoft osTicket. Vendors: Enhancesoft.

Executive brief

osTicket is a popular open-source helpdesk ticketing system. The application generates API keys—long-lived credentials used to access and modify ticket data—using a weak cryptographic method (MD5) combined with predictable information like timestamps and IP addresses. An attacker who obtains a leaked API key hash can recover the actual key through brute-force attack, gaining unauthorized access to all tickets, the ability to create tickets as other users, and permission to trigger administrative tasks.

Technical details

The vulnerability is a use of broken cryptographic algorithms (CWE-327) and weak PRNG (CWE-338) in the API key generation function. osTicket's include/class.api.php (line 149) constructs API keys as md5(time() . $vars['ipaddr'] . md5(Misc::randCode(16))). MD5 is cryptographically broken and can be computed at billions of hashes per second on GPUs. The inputs are also predictable: Unix timestamps can be approximated from logs or ticket metadata, and client IP addresses are often observable or documented. An attacker with a leaked API key hash, approximate creation time, and the target IP can materially reduce the search space and recover the key via brute-force. No authentication is required to exploit a recovered key; admin credentials are only needed to initially generate it. As of the advisory publication, no patched version had been released. The remediation is to use a cryptographically secure PRNG (e.g., bin2hex(random_bytes(32))) instead of MD5 and remove dependency on timestamp and IP address.

Affected products

  • Enhancesoft LLC osTicket <= 1.18.3

Timeline

  • 2026-08-03: disclosed
  • other: Unpatched as of advisory publication

References