CVE-2026-38447Disclosure

LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

2.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-03); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-03: 1Mentions · 2026-08-07: 1PoC Mentioned / Linked · 2026-08-07: 1Patch / Workaround · 2026-08-07: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-07: 108-0308-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • HOL@HashgraphOnline
    Disclosure

    CVE-2026-38447 (CVSS 9.8): osTicket (5M+ users, 15K+ businesses) generates API keys using MD5(timestamp, IP, seed). An attacker who approximates the generation time can brute-force the key space. One valid key unlocks the entire ticketing system. Fixed via CSPRNG replacement. https://hol.org/blog/cve-2026-38447-osticket-predictable-api-keys

    Post summary

    The blog post announces CVE-2026-38447, detailing its severe vulnerability involving predictable API key generation in osTicket, the attack vector, and notes that the issue has been fixed by replacing the key generation algorithm with a CSPRNG.

    040501.1K
    19.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-38447 Predictable API Key Generation in osTicket 1.18.3 via MD5 Hashing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-38447

    Post summary

    A CVE details a flaw in osTicket 1.18.3 that results in predictable API keys generated with MD5 hashing. The post does not provide a PoC, exploit code, active exploitation evidence, or patch information.

    0000095
    4.1K followersView on X

Explore more