osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-331 | |
| Metrics |
cvssV3_1
|
Mon, 03 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Osticket
Osticket osticket |
|
| Vendors & Products |
Osticket
Osticket osticket |
Mon, 03 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window. | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-03T19:34:16.703Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38447
Updated: 2026-08-03T19:34:12.599Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T19:30:04Z