CVE Explorer
CVE-2026-38447
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-331","description":"CWE-331 Insufficient Entropy","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-331","description":"CWE-331 Insufficient Entropy","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38447.md"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/cna/references/3
{"url":"https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.api.php#L149"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/cna/references/0
{"url":"https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.misc.php"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/cna/references/1
{"url":"https://github.com/osTicket/osTicket/commit/feccb6a3a90863fd31215ee738b39762177e658c"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f7b96668eb5ce6e5b535c8b7d031b85e1e21f7bae725051d919ebb37e68fcf07 · sha256:4b041631f952654b… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.