CVE-2026-14871
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
- Affected products
- Osticket
- CVSS 4.0
- 7.1 HIGH
- EPSS
- 0.4% (36th percentile)
- Weakness
- CWE-863
- NVD status
- Awaiting Analysis
- Published
- 2026-07-17
- Attack patterns
- CAPEC-21
CVE-2026-14871 at NVD
1 known exploit for CVE-2026-14871
Proof-of-concept code and exploit modules indexed by Sploitus