Vulnerability Description
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/kyokai
- https://github.com/osTicket/osTicket/
- https://github.com/osTicket/osTicket/releases/tag/v1.17.8
- https://github.com/osTicket/osTicket/releases/tag/v1.18.4
- https://medium.com/p/1abb8be847e6
FAQ
What is CVE-2026-14871?
CVE-2026-14871 is a documented vulnerability. osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
How severe is CVE-2026-14871?
CVSS scoring is not yet available for CVE-2026-14871. Check NVD for updates.
Is there a patch for CVE-2026-14871?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.