CVE-2026-38447

osTicket 1.

criticalEPSS 0.7%

Description

osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.

Metrics

9.8
Source: nvd-v3
50.6 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-03 00:00 UTC

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-08-03 19:16 UTC· cve@mitre.org
    • Affected: n/a
    • Description: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
    • Reference: https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38447.md
    • Reference: https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.api.php#L149

Linked advisories