User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform. | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-02T18:05:15.423Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26895
Updated: 2026-04-02T18:03:30.376Z
Status : Received
Published: 2026-04-02T17:16:21.833
Modified: 2026-04-02T19:21:24.383
Link: CVE-2026-26895
No data.
OpenCVE Enrichment
No data.
Weaknesses