CVE-2026-26895

User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*

History

07 Apr 2026, 16:01

Type Values Removed Values Added
First Time Enhancesoft osticket
Enhancesoft
References () http://osticket.com - () http://osticket.com - Product
References () https://csacyber.com/blog/osticket-timing-vulnerability-understanding-the-risk - () https://csacyber.com/blog/osticket-timing-vulnerability-understanding-the-risk - Exploit, Third Party Advisory
CPE cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*

02 Apr 2026, 19:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-203

02 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 17:16

Updated : 2026-04-07 16:01


NVD link : CVE-2026-26895

Mitre link : CVE-2026-26895

CVE.ORG link : CVE-2026-26895


JSON object : View

Products Affected

enhancesoft

  • osticket
CWE
CWE-203

Observable Discrepancy