CVE-2026-36214

MEDIUM

osTicket 1.10-1.17.7 and 1.18.0-1.18.3 - Stored Cross-Site Scripting via Bootstrap Tooltip Component

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2026-36214. PoCs published by amnsecurity, WesWrench, HORKimhab.

AI-analyzed exploit summary This repository provides a detailed technical analysis and proof-of-concept for CVE-2026-36214, a stored XSS vulnerability in osTicket via Bootstrap Tooltip 3.3.4 (CVE-2019-8331). The exploit leverages unauthenticated file uploads and crafted HTML payloads to execute JavaScript in agent/admin sessions.

Description

osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or Admin sessions.

Exploits (3)

github WRITEUP 1 stars
by amnsecurity · pythonpoc
https://github.com/amnsecurity/CVE-2026-36214-osTicket-XSS

This repository provides a detailed technical analysis and proof-of-concept for CVE-2026-36214, a stored XSS vulnerability in osTicket via Bootstrap Tooltip 3.3.4 (CVE-2019-8331). The exploit leverages unauthenticated file uploads and crafted HTML payloads to execute JavaScript in agent/admin sessions.

Classification
Writeup 98%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: osTicket v1.10-v1.17.7, v1.18.0-v1.18.3
No auth needed
Prerequisites: Target must allow unauthenticated file uploads (default in affected versions) · Agent/admin must open the malicious ticket · Bootstrap Tooltip 3.3.4 must be present (unpatched)
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →
nomisec WRITEUP 1 stars
by WesWrench · poc
https://github.com/WesWrench/CVE-2026-36214

This repository provides a detailed technical analysis of CVE-2026-36214, a stored XSS vulnerability in osTicket via a vulnerable Bootstrap Tooltip component (CVE-2019-8331). The writeup explains how unauthenticated users can upload malicious JavaScript files and craft payloads to execute arbitrary JavaScript in the context of authenticated Agents or Admins, bypassing HTML sanitization and CSP restrictions.

Classification
Writeup 98%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: osTicket versions 1.10 to 1.17.7 and 1.18.0 to 1.18.3
No auth needed
Prerequisites: Default osTicket configuration (open user self-registration and unrestricted file uploads) · Agent/Admin interaction with the malicious ticket
mistral-large-3 · analyzed Jul 15, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/36xxx/CVE-2026-36214.md

The repository contains no technical details or exploit code for CVE-2026-36214. Instead, it links to external GitHub repositories and encrypted archives, which is a common tactic for social engineering or malware distribution.

Classification
Suspicious 98%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unspecified
No auth needed
Prerequisites: external download required
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →

Scores

CVSS v3 5.4
EPSS 0.0033
EPSS Percentile 25.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published Jul 14, 2026
Tracked Since Jul 14, 2026