high CVSS 7.5

CVE-2026-22200·PHP vulnerability

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.

Severity
high
Software
PHP
Fixed in
1.18.3
Published
2026-01-12

Affected versions

From: 1.18

Until: 1.18.3

Fixed in: 1.18.3

How to fix this CVE

Upgrade osTicket to version 1.18.3 or later to patch the arbitrary file read vulnerability in the PDF export feature. This vulnerability allows attackers to embed sensitive server files into exported PDFs through malicious HTML in ticket submissions. Update PHP and osTicket immediately if you are running versions 1.18.0 through 1.18.2, particularly if your instance allows guest ticket creation or self-registration.

sudo dnf check-update php && sudo dnf upgrade php

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

POST /api/tickets/ HTTP/1.1.*\nContent-Type: application/x-www-form-urlencoded.*\n.*html.*php://filter.*|POST.*export.*pdf.*\nReferer:.*tickets\.php.*

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Block POST requests to `/api/tickets/` and `/scp/tickets.php` containing `php://filter` expressions in HTML form fields or request bodies; implement input validation to reject HTML containing filter stream wrappers before PDF generation

How to check if you are affected

  1. Run `php -v` to confirm your PHP version and verify it matches the version used by your osTicket installation
  2. Check your osTicket installation directory for the version file: `grep -i version /path/to/osticket/include/osticket.h | head -5`
  3. Search your web server access and error logs for POST requests to `/api/tickets/` or `/scp/tickets.php` with `pdf` or `export` parameters: `grep -i 'export\|pdf' /var/log/apache2/access.log | grep POST`
  4. Verify the patch by checking the osTicket release notes or comparing file checksums of `/include/` and `/api/` directories against the official v1.18.3 release

FAQ

What is CVE-2026-22200?

CVE-2026-22200 is an arbitrary file read vulnerability in osTicket's PDF export functionality that allows attackers to embed sensitive server files into generated PDFs by injecting malicious HTML and PHP filter expressions into ticket submissions.

Is CVE-2026-22200 being actively exploited?

No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been released, though detailed technical analysis is publicly available.

What versions of osTicket are affected by CVE-2026-22200?

osTicket versions 1.18.0 through 1.18.2 are vulnerable; version 1.18.3 and later include the fix. Additionally, 1.17.x versions prior to 1.17.7 are affected.

How do I check if my server is vulnerable to CVE-2026-22200?

Locate your osTicket installation and run: `grep -E 'VERSION|version' /path/to/osticket/bootstrap.php | head -3` then compare against 1.18.3; if your version is below 1.18.3, your instance is vulnerable.

Does Defensia detect CVE-2026-22200?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP and osTicket are installed on a monitored server, CVE-2026-22200 will appear in your dashboard with remediation steps.

Related PHP CVEs

CVE-2026-28289CVSS 10FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnerability exists in the sanitizeUploadedFileName() function in app/Http/Helper.php. The function contains a Time-of-Check to Time-of-Use (TOCTOU) flaw where the dot-prefix check occurs before sanitization removes invisible characters. This vulnerability is fixed in 1.8.207.
CVE-2025-46348CVSS 10YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and download an archive without being authenticated. This could result in a malicious attacker making numerous requests to create archives and fill up the file system, or by downloading the archive which contains sensitive site information. This issue has been patched in version 4.5.4.
CVE-2025-47916CVSS 10Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings.
CVE-2025-25174CVSS 10Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extensions beeteam368-extensions allows PHP Local File Inclusion.This issue affects BeeTeam368 Extensions: from n/a through <= 1.9.4.
CVE-2025-62521CVSS 10ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The vulnerability exists in `setup/routes/setup.php` where user input from the setup form is directly concatenated into a PHP configuration template without any validation or sanitization. Any parameter in the setup form can be used to inject PHP code that gets written to `Include/Config.php`, which is then executed on every page load. This is more severe than typical authenticated RCE vulnerabilities because it requires no credentials and affects the installation process that administrators must complete. Version 5.21.0 patches the issue.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-22200. Free for 1 server.

Get started free