CVE-2026-38447: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-38447
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-38447 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for osTicket
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-38446: A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sa…nvd · 2026-08-03
- unknownCVE-2026-38444: osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header …nvd · 2026-08-03
- unknownCVE-2026-18363: A logic vulnerability in the password reset token validation routine implemented by osTicket i…nvd · 2026-07-30
- unknownCVE-2026-14871: osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leadi…nvd · 2026-07-17
- mediumCVE-2026-36214: osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stor…nvd · 2026-07-14
More from NVD Recent CVEs
- highCVE-2026-59913: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missin…2026-08-03
- highCVE-2026-59912: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Impro…2026-08-03
- unknownCVE-2026-38446: A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sa…2026-08-03
- unknownCVE-2026-38444: osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header …2026-08-03
- criticalCVE-2026-18616: A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the f…2026-08-03