CVE-2026-38446 Details
Description
A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.
A stored cross-site scripting vulnerability has been identified in osTicket version 1.18.3. This issue arises from inadequate sanitization of user input in the thread entry title, which is derived from email subject lines or ticket titles. The vulnerability allows an attacker to inject arbitrary JavaScript by sending a crafted ticket reply or email with a malicious subject. The injected script is executed in the context of the user viewing the ticket thread, potentially leading to session theft, account takeover, and unauthorized actions as a staff member.
The vulnerability has been addressed in osTicket version 1.18.4. Users should update to this version. Instructions for updating osTicket can be found in the osTicket documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 3, 2026CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| osTicket | <= 1.18.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |
Volerion