Vulnerability record · CVE-2026-22200 · published 12 January 2026
CVE-2026-22200: osTicket PDF export PHP filter injection allows arbitrary file read
Enhancesoft · Osticket
osTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 fail to sanitize rich-text HTML in tickets before it is processed by the mPDF generator during PDF export. Crafted PHP filter expressions embedded in a ticket cause the exported PDF to render attacker-selected server files as bitmap images. This exposes sensitive local files readable by the osTicket application user.
Description
Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityUnauthenticated remote file read in default configurations with a public exploit and very high EPSS, though no KEV listing or observed ransomware use.
What it is
osTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 fail to sanitize rich-text HTML in tickets before it is processed by the mPDF generator during PDF export. Crafted PHP filter expressions embedded in a ticket cause the exported PDF to render attacker-selected server files as bitmap images. This exposes sensitive local files readable by the osTicket application user.
Impact
An unauthenticated remote attacker can read arbitrary files on the server within the privileges of the osTicket application user, potentially exposing configuration files, credentials and other sensitive data. There is no integrity or availability impact; the gain is confidential data disclosure.
Attack surface
Reached over the network by submitting a ticket with crafted rich-text HTML and then exporting it to PDF. No authentication or user interaction is required in default configurations where guests can create tickets and view ticket status, or where self-registration is enabled.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.739, 99.5th percentile) and a public exploit write-up is referenced, indicating active interest and likely working exploitation.
What to do
- Upgrade to osTicket 1.18.3 or 1.17.7 (or later) to apply the vendor patch.
- If immediate patching is not possible, restrict guest ticket creation and self-registration, and limit PDF export to trusted staff.
- Disable or restrict the ticket PDF export feature until the patch is applied.
- Run osTicket with a least-privilege application user and restrict filesystem permissions to limit what files can be read.
- Monitor vendor advisories and the referenced patch commit for backport guidance.
Detection
- Monitor for tickets containing PHP filter syntax such as php://filter or convert.base64-encode in rich-text fields.
- Alert on PDF export requests from guest or unauthenticated sessions, especially repeated exports of the same ticket.
- Review web and application logs for unusual file access patterns by the osTicket process user.
- Inspect generated PDFs for embedded bitmap images that may contain file contents.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-22200 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-22200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.