← Vulnerability feed

Vulnerability record · CVE-2026-22200 · published 12 January 2026

CVE-2026-22200: osTicket PDF export PHP filter injection allows arbitrary file read

Enhancesoft · Osticket

osTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 fail to sanitize rich-text HTML in tickets before it is processed by the mPDF generator during PDF export. Crafted PHP filter expressions embedded in a ticket cause the exported PDF to render attacker-selected server files as bitmap images. This exposes sensitive local files readable by the osTicket application user.

8.7 CVSS 4.0 High EPSS 74% · top 0.5% CWE-74 · Injection
8.7CVSS 4.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 1 tagged exploit
14 Jul 2026Last modified by NVD

Description

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote file read in default configurations with a public exploit and very high EPSS, though no KEV listing or observed ransomware use.

What it is

osTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 fail to sanitize rich-text HTML in tickets before it is processed by the mPDF generator during PDF export. Crafted PHP filter expressions embedded in a ticket cause the exported PDF to render attacker-selected server files as bitmap images. This exposes sensitive local files readable by the osTicket application user.

Impact

An unauthenticated remote attacker can read arbitrary files on the server within the privileges of the osTicket application user, potentially exposing configuration files, credentials and other sensitive data. There is no integrity or availability impact; the gain is confidential data disclosure.

Attack surface

Reached over the network by submitting a ticket with crafted rich-text HTML and then exporting it to PDF. No authentication or user interaction is required in default configurations where guests can create tickets and view ticket status, or where self-registration is enabled.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.739, 99.5th percentile) and a public exploit write-up is referenced, indicating active interest and likely working exploitation.

What to do

  • Upgrade to osTicket 1.18.3 or 1.17.7 (or later) to apply the vendor patch.
  • If immediate patching is not possible, restrict guest ticket creation and self-registration, and limit PDF export to trusted staff.
  • Disable or restrict the ticket PDF export feature until the patch is applied.
  • Run osTicket with a least-privilege application user and restrict filesystem permissions to limit what files can be read.
  • Monitor vendor advisories and the referenced patch commit for backport guidance.

Detection

  • Monitor for tickets containing PHP filter syntax such as php://filter or convert.base64-encode in rich-text fields.
  • Alert on PDF export requests from guest or unauthenticated sessions, especially repeated exports of the same ticket.
  • Review web and application logs for unusual file access patterns by the osTicket process user.
  • Inspect generated PDFs for embedded bitmap images that may contain file contents.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22200 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42235Enhancesoft osticket sql injection vulnerabilitySQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile fu…EPSS 1.0%9.8CVE-2020-24881osTicket SSRF allows file upload and port scanningosTicket before 1.14.3 contains a server-side request forgery flaw. An attacker can use it to add a malicious file to the server or perform port scan…EPSS 73%analysed8.8CVE-2022-31888Enhancesoft osticket vulnerabilitySession Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.EPSS 1.2%8.8CVE-2019-14749Enhancesoft osticket csv injection vulnerabilityAn issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionali…EPSS 9.6%8.1CVE-2018-7195Enhancesoft osticket vulnerabilityEnhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging gu…EPSS 1.00%7.5CVE-2023-30082Enhancesoft osticket vulnerabilityA denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using th…EPSS 1.00%7.5CVE-2010-0605Enhancesoft osticket sql injection vulnerabilitySQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute a…EPSS 3.0%7.5CVE-2009-2361Enhancesoft osticket sql injection vulnerabilitySQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the s…EPSS 5.2%

Source: NIST National Vulnerability Database (record CVE-2026-22200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.