Junglewise Threat Intelligence

CVE-2026-9507: Enhancesoft osTicket session fixation in OSTSESSID

CVE-2026-9507 · Severity: info · CVSS 5.1 · Published 2026-06-16

Executive brief

osTicket is an open-source support ticket system used by organizations to manage customer inquiries. A security flaw allows an attacker to potentially take over a user's account if they can trick the user into using a specific session ID before logging in. This could lead to unauthorized access to sensitive support tickets and customer data.

Technical details

A session fixation vulnerability exists in osTicket v1.18.2 due to the application's failure to invalidate the pre-authentication session cookie or rotate the session identifier upon successful user authentication. An attacker can exploit this by pre-setting a known OSTSESSID in a victim's browser (e.g., via CRLF injection or physical access). Once the victim authenticates using that fixed session ID, the attacker can use the same identifier to gain unauthorized access to the authenticated session. The vendor has indicated that the legacy codebase is in maintenance mode with delayed security updates as they focus on a version 2.0 rewrite.

Affected products

  • Enhancesoft osTicket 1.18.2

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory

References

Related threats