PT-2026-2291 · Mpdf+1 · Mpdf+1

Naveen Sunkavally

·

Published

2026-01-12

·

Updated

2026-05-01

·

CVE-2026-22200

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions osTicket versions 1.17.x prior to 1.17.7 and 1.18.x prior to 1.18.3
Description osTicket versions 1.17.x prior to 1.17.7 and 1.18.x prior to 1.18.3 contain an arbitrary file read issue in the ticket PDF export functionality. An attacker can submit a ticket with crafted rich-text HTML containing PHP filter expressions that are not properly sanitized before being processed by the mPDF PDF generator during export. Exporting the ticket to PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, potentially disclosing sensitive local files within the context of the osTicket application user. This is exploitable in default configurations where guests can create tickets and access ticket status, or where self-registration is enabled. The issue allows for the reading of arbitrary server files, including sensitive configuration data such as database credentials and secret key material.
Recommendations Update to osTicket version 1.17.7 or later. Update to osTicket version 1.18.3 or later.

Exploit

Fix

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22200

Affected Products

Mpdf
Osticket