CVE-2026-18363

Description

A flaw was found in osTicket. A logic vulnerability in the password reset token validation routine allows an attacker to bypass the intended expiry validation. By obtaining and reusing a valid password reset token, a remote attacker can perform an unauthorized password reset, leading to the compromise of an affected user account.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

An attacker could gain unauthorized access to the system by retrieving legitimate user's authentication credentials.

Availability

Technical Impact: DoS: Resource Consumption (Other)

An attacker could deny service to legitimate system users by launching a brute force attack on the password recovery mechanism using user ids of legitimate users.

Integrity,Other

Technical Impact: Other

The system's security functionality is turned against the system by the attacker.

Frequently Asked Questions

Want to get errata notifications? Sign up here.