User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
References
| Link | Resource |
|---|---|
| https://csacyber.com/blog/osticket-timing-vulnerability-understanding-the-risk | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-04-02 17:16
Updated : 2026-07-24 21:10
NVD link : CVE-2026-26895
Mitre link : CVE-2026-26895
CVE.ORG link : CVE-2026-26895
JSON object : View
Products Affected
enhancesoft
- osticket
CWE
CWE-203
Observable Discrepancy
