CVE-2026-22200·PHP vulnerability
Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.
- Severity
- high
- Software
- PHP
- Fixed in
- 1.18.3
- Published
- 2026-01-12
Affected versions
From: 1.18
Until: 1.18.3
Fixed in: 1.18.3
How to fix this CVE
Upgrade osTicket to version 1.18.3 or later to patch the arbitrary file read vulnerability in the PDF export feature. This vulnerability allows attackers to embed sensitive server files into exported PDFs through malicious HTML in ticket submissions. Update PHP and osTicket immediately if you are running versions 1.18.0 through 1.18.2, particularly if your instance allows guest ticket creation or self-registration.
sudo dnf check-update php && sudo dnf upgrade phpDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /api/tickets/ HTTP/1.1.*\nContent-Type: application/x-www-form-urlencoded.*\n.*html.*php://filter.*|POST.*export.*pdf.*\nReferer:.*tickets\.php.*WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block POST requests to `/api/tickets/` and `/scp/tickets.php` containing `php://filter` expressions in HTML form fields or request bodies; implement input validation to reject HTML containing filter stream wrappers before PDF generationHow to check if you are affected
- Run `php -v` to confirm your PHP version and verify it matches the version used by your osTicket installation
- Check your osTicket installation directory for the version file: `grep -i version /path/to/osticket/include/osticket.h | head -5`
- Search your web server access and error logs for POST requests to `/api/tickets/` or `/scp/tickets.php` with `pdf` or `export` parameters: `grep -i 'export\|pdf' /var/log/apache2/access.log | grep POST`
- Verify the patch by checking the osTicket release notes or comparing file checksums of `/include/` and `/api/` directories against the official v1.18.3 release
FAQ
What is CVE-2026-22200?
CVE-2026-22200 is an arbitrary file read vulnerability in osTicket's PDF export functionality that allows attackers to embed sensitive server files into generated PDFs by injecting malicious HTML and PHP filter expressions into ticket submissions.
Is CVE-2026-22200 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been released, though detailed technical analysis is publicly available.
What versions of osTicket are affected by CVE-2026-22200?
osTicket versions 1.18.0 through 1.18.2 are vulnerable; version 1.18.3 and later include the fix. Additionally, 1.17.x versions prior to 1.17.7 are affected.
How do I check if my server is vulnerable to CVE-2026-22200?
Locate your osTicket installation and run: `grep -E 'VERSION|version' /path/to/osticket/bootstrap.php | head -3` then compare against 1.18.3; if your version is below 1.18.3, your instance is vulnerable.
Does Defensia detect CVE-2026-22200?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP and osTicket are installed on a monitored server, CVE-2026-22200 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
- https://github.com/osTicket/osTicket/commit/c59b067
- https://github.com/osTicket/osTicket/releases/tag/v1.17.7
- https://github.com/osTicket/osTicket/releases/tag/v1.18.3
- https://horizon3.ai/attack-research/attack-blogs/ticket-to-shell-exploiting-php-filters-and-cnext-in-osticket-cve-2026-22200/
- https://www.vulncheck.com/advisories/osticket-pdf-export-arbitrary-file-read
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-22200. Free for 1 server.
Get started free