CVE-2026-26895: Medium severity Enhancesoft osTicket vulnerability
Published Apr 2, 2026
·Updated
User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
Affected Software
1 affected component
Enhancesoft osTicket<1.18.3
Event History
Apr 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26895?
CVE-2026-26895 has a medium severity rating of 5.3 according to the CVSS 3.1 metrics.
2
What is CVE-2026-26895?
CVE-2026-26895 is a user enumeration vulnerability in /pwreset.php of osTicket v1.18.2 that allows attackers to identify valid usernames on the platform.
3
How do I fix CVE-2026-26895?
To fix CVE-2026-26895, you should upgrade to the latest version of osTicket that addresses this vulnerability.
4
Where can I find more information about CVE-2026-26895?
More information about CVE-2026-26895 can be found on the official osTicket website and relevant security blogs.
5
What are the implications of CVE-2026-26895?
The implications of CVE-2026-26895 include the risk of attackers successfully identifying valid usernames, which can lead to further attacks.