CVE-2026-36214
EUVD-2026-4375414.07.2026, 17:16
osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or Admin sessions.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| osticket | osticket | 1.10.0 ≤ 𝑥 < 1.17.8 | CNA |
| osticket | osticket | 1.18.0 ≤ 𝑥 < 1.18.4 | CNA |
References