CVE-2026-22200

HIGH NUCLEI

Enhancesoft osTicket 1.17.0-1.17.6 and 1.18.0-1.18.2 - Unauthenticated Arbitrary File Read via Ticket PDF Export

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-22200. PoCs published by horizon3ai, Remnant-DB, HORIZON3.ai Team, Arkaprabha Chakraborty <@t1nt1nsn0wy>, including Metasploit module auxiliary/gather/osticket_arbitrary_file_read. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2026-22200, which abuses PHP filters in osTicket's mPDF library to exfiltrate files and can be chained with CVE-2024-2961 for remote code execution (RCE). The exploit includes checks for vulnerability validation and payload generation tools.

Description

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.

Exploits (3)

nomisec WORKING POC 8 stars
by horizon3ai · poc
https://github.com/horizon3ai/CVE-2026-22200

This repository contains a proof-of-concept exploit for CVE-2026-22200, which abuses PHP filters in osTicket's mPDF library to exfiltrate files and can be chained with CVE-2024-2961 for remote code execution (RCE). The exploit includes checks for vulnerability validation and payload generation tools.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: osTicket (versions prior to 1.18.3 and 1.17.7)
No auth needed
Prerequisites: Access to the target osTicket installation · Public account registration or open ticket access enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Remnant-DB · poc
https://github.com/Remnant-DB/CVE-2026-22200

This repository provides a containerized lab environment for osTicket 1.18.1, which is vulnerable to CVE-2026-22200. It includes Docker and Podman configurations to deploy a controlled testing environment for defensive validation and secure configuration testing.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: osTicket 1.18.1
No auth needed
Prerequisites: Docker or Podman installed · Outbound network access for downloading osTicket
devstral-2 · analyzed Apr 09, 2026 Full analysis →
metasploit WORKING POC
by HORIZON3.ai Team, Arkaprabha Chakraborty <@t1nt1nsn0wy> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/osticket_arbitrary_file_read.rb

This Metasploit module exploits CVE-2026-22200, an arbitrary file read vulnerability in osTicket via PHP filter chains in mPDF. It authenticates, injects a crafted HTML payload into a ticket reply, and extracts file contents from the generated PDF.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: osTicket (versions affected by CVE-2026-22200)
Auth required
Prerequisites: valid credentials · existing or new ticket number
devstral-2 · analyzed Apr 09, 2026 Full analysis →

Nuclei Templates (1)

osTicket - Arbitrary File Read
HIGHVERIFIEDby DhiyaneshDk
Shodan: html:"osTicket"

Scores

CVSS v3 7.5
EPSS 0.6687
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-74
Status published
Products (3)
enhancesoft/osticket 1.17 - 1.17.7
Enhancesoft/osTicket 1.17.0 - 1.17.7
Enhancesoft/osTicket 1.18.0 - 1.18.3
Published Jan 12, 2026
Tracked Since Feb 18, 2026