CVE-2026-22200Exploit(enhancesoft / osticket)

HIGHCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch enhancesoft osticket systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • osticket

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-03-01); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
osticket

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-01: 1Mentions · 2026-04-10: 1Mentions · 2026-05-01: 1PoC Mentioned / Linked · 2026-03-01: 1PoC Mentioned / Linked · 2026-05-01: 1Exploit Tool / Code · 2026-04-10: 1Exploit Tool / Code · 2026-05-01: 1Active Exploitation · 2026-05-01: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-03-01: 1Technical Details · 2026-04-10: 1Technical Details · 2026-05-01: 103-0104-1005-01
Signal classification2 categories
Exploit
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-011
PoC1
2026-04-101
Exploit1
2026-05-011
Exploit1
Full discourse3 posts
  • Metasploit Project@metasploit
    Exploit

    This week's release features a 2x faster msfvenom bootup time and new modules, including exploits for the Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20127) and osTicket Arbitrary File Read (CVE-2026-22200). https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-10-2026/

    Post summary

    Rapid7’s latest Metasploit update introduces new exploit modules for CVE‑2026‑20127 and CVE‑2026‑22200, providing functional attack code for these vulnerabilities.

    012045164.8K
    253.4K followersView on X
  • 𝕊𝟜𝕞𝟜𝟛𝕝 𝟘𝕩𝟜 ☠@nerdByt
    PoC

    🚨 CVE-2026-22200 — Confirmed & Validated [ osTicket Arbitrary File Read ] Manual validation ✔ Root cause analysis ✔ "/etc/hosts" manipulation for controlled testing ✔ 🔗 https://github.com/samael0x4/CVE-2026/tree/main/2026/CVE-2026-22200 #CVE #BugBounty #OffensiveSecurity #AppSec #CVE202622200 #nuclei #osTicket

    Post summary

    CVE-2026-22200, an arbitrary file read vulnerability in osTicket, has been confirmed and validated with a PoC available on GitHub.

    00010109
    37 followersView on X
  • Yasir Raza@yasirrazahaidry
    Exploit

    Metasploit 6.4.126 adds modules for CVE-2026-20127, a Cisco SD-WAN auth bypass exploited in the wild as a zero-day, and CVE-2026-22200, an osTicket arbitrary file read. Patch exposed systems now. https://www.ra... https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-04-10-2026

    Post summary

    Rapid7 released new Metasploit modules for CVE-2026-20127 (a Cisco SD‑WAN auth bypass exploited in the wild) and CVE-2026-22200 (an osTicket arbitrary file read), and patches are now available.

    00000116
    908 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appenhancesoftosticket---

Explore more