CVE-2026-14871: osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure
Published Jul 17, 2026
·Updated
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Affected Software
1 affected component
osTicket osTicket>=1.17.7<=1.18.3
Event History
Jul 17, 2026
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14871?
CVE-2026-14871 has a high severity rating of 7.1.
2
How do I fix CVE-2026-14871?
To fix CVE-2026-14871, upgrade to a patched version of osTicket beyond v1.18.3 and v1.17.7.
3
What does CVE-2026-14871 exploit in osTicket?
CVE-2026-14871 exploits a Broken Object Level Authorization leading to Insecure Direct Object Reference in osTicket.
4
What are the affected versions of osTicket for CVE-2026-14871?
The affected versions for CVE-2026-14871 are osTicket v1.18.3 and v1.17.7.
5
What impact does CVE-2026-14871 have on data security?
CVE-2026-14871 allows for cross-department data disclosure due to improper authorization in ticket field viewing.