Vulnerability Description
User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enhancesoft | Osticket | < 1.18.3 |
Related Weaknesses (CWE)
References
- http://osticket.comProduct
- https://csacyber.com/blog/osticket-timing-vulnerability-understanding-the-riskExploitThird Party Advisory
FAQ
What is CVE-2026-26895?
CVE-2026-26895 is a vulnerability with a CVSS score of 5.3 (MEDIUM). User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
How severe is CVE-2026-26895?
CVE-2026-26895 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-26895?
Check the references section above for vendor advisories and patch information. Affected products include: Enhancesoft Osticket.