User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
References
| Link | Resource |
|---|---|
| http://osticket.com | Product |
| https://csacyber.com/blog/osticket-timing-vulnerability-understanding-the-risk | Exploit Third Party Advisory |
Configurations
History
07 Apr 2026, 16:01
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Enhancesoft osticket
Enhancesoft |
|
| References | () http://osticket.com - Product | |
| References | () https://csacyber.com/blog/osticket-timing-vulnerability-understanding-the-risk - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:* |
02 Apr 2026, 19:21
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CWE | CWE-203 |
02 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-02 17:16
Updated : 2026-04-07 16:01
NVD link : CVE-2026-26895
Mitre link : CVE-2026-26895
CVE.ORG link : CVE-2026-26895
JSON object : View
Products Affected
enhancesoft
- osticket
CWE
CWE-203
Observable Discrepancy
