Sploitus

CVE-2026-8194

No indexed exploits for CVE-2026-8194 yet

A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argument _method leads to cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

Affected products
Osticket
CVSS 4.0
5.3 MEDIUM
CVSS 3.1
4.3 MEDIUM
EPSS
0.2% (6th percentile)
Weakness
CWE-352, CWE-862
NVD status
Deferred
Published
2026-05-09
CVE-2026-8194 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-8194 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-8194 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.