Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.
CVE-2026-22200
Score elevated to 8.7 because EPSS predicts 73% probability of exploitation within the next 30 days (top 0.6% of all CVEs). NVD baseline CVSS 7.5 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 73%
- Public exploit code is available (Metasploit, epss top5pct, epss high, public exploit)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.5
- EG Score
- 8.7(high)
- EG Risk
- 83(Track)EG Risk 83/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity87% × 45%Exploitation73% × 40%Automatability100% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 73%
- EPSS %ILE
- 99%
- KEV
- Not listed
Published
January 12, 2026
Last Modified
July 14, 2026
Advisory Details (5)
Auto-updated Jul 16, 2026osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read | Advisories | VulnCheck
https://www.vulncheck.com/advisories/osticket-pdf-export-arbitrary-file-readCVE-2026-22200: Ticket to Shell in osTicket | Horizon3.ai
https://horizon3.ai/attack-research/attack-blogs/ticket-to-shell-exploiting-php-filters-and-cnext-in-osticket-cve-2026-22200/v1.18.3
Patch available: osTicket/osTicket v1.18.3
https://github.com/osTicket/osTicket/releases/tag/v1.18.3v1.17.7
Patch available: osTicket/osTicket v1.17.7
https://github.com/osTicket/osTicket/releases/tag/v1.17.7commit c59b067 (osTicket/osTicket)
Patch available: osTicket/osTicket v1.17.7 (contains commit c59b067)
https://github.com/osTicket/osTicket/commit/c59b067Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 8× in last 7d / 28× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-25 14:17 UTCEPSS rescore
- 2026-07-25 14:17 UTCEPSS rescore
- 2026-07-24 14:17 UTCEPSS rescore
- 2026-07-23 10:49 UTCOSV refresh
- 2026-07-23 03:06 UTCEG score recompute▲ 1.20
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-14 17:20 UTCNVD updateCVSS v3 → 7.5
- 2026-07-14 16:10 UTCMITRE cvelistV5CVSS v3 → 8.7
- 2026-07-13 22:30 UTCEPSS rescore
- 2026-07-13 06:13 UTCEPSS rescore
- 2026-07-13 06:13 UTCEPSS rescore
- 2026-07-12 05:46 UTCEPSS rescore
- 2026-07-12 05:46 UTCEPSS rescore
- 2026-07-09 19:10 UTCEPSS rescore
- 2026-07-06 06:02 UTCOSV refresh
- 2026-07-05 02:30 UTCEPSS rescore
- 2026-07-01 15:06 UTCEPSS rescore
- 2026-07-01 15:06 UTCEPSS rescore
Show 40 moreShow fewer
- 2026-06-30 23:22 UTCEPSS rescore
- 2026-06-30 23:22 UTCEPSS rescore
- 2026-06-28 14:07 UTCEPSS rescore
- 2026-06-27 03:08 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-24 14:05 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-21 14:56 UTCEPSS rescore
- 2026-06-18 17:52 UTCEPSS rescore
- 2026-06-17 17:35 UTCOSV refresh
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-15 17:48 UTCEPSS rescore
- 2026-06-14 23:18 UTCEPSS rescore
- 2026-06-12 23:12 UTCEPSS rescore
- 2026-06-11 14:00 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 13:22 UTCEPSS rescore
- 2026-06-08 14:17 UTCEPSS rescore
- 2026-06-08 14:17 UTCEPSS rescore
- 2026-06-07 15:25 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-05 22:47 UTCEPSS rescore
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-05 06:10 UTCEPSS rescore
- 2026-06-04 13:12 UTCEPSS rescore
- 2026-06-04 13:12 UTCEPSS rescore
- 2026-06-04 13:12 UTCEPSS rescore
- 2026-06-02 20:13 UTCEPSS rescore
- 2026-06-02 20:13 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-29 16:18 UTCEG score recompute
- 2026-05-29 16:18 UTCGHSA enrichment
- 2026-05-29 13:44 UTCEPSS rescore
- 2026-05-29 13:44 UTCEPSS rescore
Publicly available exploits
(2 references)Working exploit code is in the public domain (1 Metasploit module). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Metasploitauxiliary/gather/osticket_arbitrary_file_read✓ verifiedFirst seen Jan 13, 2026
osTicket Arbitrary File Read via PHP Filter Chains in mPDF
Open source ↗ - Nucleihttp/cves/2026/CVE-2026-22200.yamlFirst seen Jan 1, 2026
osTicket - Arbitrary File Read
Open source ↗
Frequently asked(5)
What is CVE-2026-22200?
When was CVE-2026-22200 disclosed?
Is CVE-2026-22200 actively exploited?
What is the CVSS score of CVE-2026-22200?
How do I remediate CVE-2026-22200?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-22200
Is Your Infrastructure Affected by CVE-2026-22200?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.