CVE-2026-14871EPSS p34.9%
CVE-2026-14871CVE-2026-14871
Description
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Scoring
| EPSS | 0.43% probability of exploitation · percentile 34.9% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-17 |