CVE Explorer
CVE-2026-18363
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tokens with an existing timestamp to bypass the intended expiry validation. Therefore, an attacker able
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"osTicket","vendor":"Enhancesoft LLC","versions":[{"lessThan":"1.17.8","status":"affected","version":"0","versionType":"custom"},{"lessThan":"1.18.4","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:78f859a7c78579d49988e14b672fe418c83d993ccde5a8c0bbbf38c759bbf6e4 · sha256:8532de1f060d2ad9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":9.1,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityIm…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:78f859a7c78579d49988e14b672fe418c83d993ccde5a8c0bbbf38c759bbf6e4 · sha256:8532de1f060d2ad9… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-640","description":"CWE-640 Weak Password Recovery Mechanism for Forgotten Password","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:78f859a7c78579d49988e14b672fe418c83d993ccde5a8c0bbbf38c759bbf6e4 · sha256:8532de1f060d2ad9… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["patch"],"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/weak-password-recovery-mechanism-osticket-enhancesoft-llc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:78f859a7c78579d49988e14b672fe418c83d993ccde5a8c0bbbf38c759bbf6e4 · sha256:8532de1f060d2ad9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.