Appsecure logo

CVE-2026-22200: High Vulnerability in Enhancesoft osTicket

A high-severity arbitrary file read vulnerability exists in Enhancesoft osTicket that allows attackers to read sensitive files via crafted ticket submissions. Immediate action is required to patch vulnerable versions.

HIGHPublic ExploitCVSS 8.7 · Published January 12, 2026

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

CVE-2026-22200 is a high-severity vulnerability affecting Enhancesoft's osTicket. The CVSS score of 8.7 highlights the critical nature of this flaw. This vulnerability allows a remote attacker to exploit the ticket PDF export functionality to read arbitrary files from the server's filesystem. Attackers can craft tickets containing rich-text HTML with PHP filter expressions, which are insufficiently sanitized before being processed. This exploit can lead to the disclosure of sensitive files in the context of the osTicket application user.

This issue is particularly dangerous in default configurations where guests can create tickets or where self-registration is enabled. Organizations using affected versions of osTicket must act quickly. Immediate patching is crucial to mitigate the risk of data exposure.

Understanding the real-world risk context is vital. If exploited, this vulnerability could lead to significant information leakage, potentially impacting user privacy and organizational integrity. Given the urgency of the situation, organizations should prioritize patching immediately.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.