CVE-2026-38447
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
취약점 유형
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
참고 자료
- https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38447.md
- https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.api.php#L149
- https://github.com/osTicket/osTicket/blob/v1.18.3/include/class.misc.php
- https://github.com/osTicket/osTicket/commit/feccb6a3a90863fd31215ee738b39762177e658c
공격자보다 먼저 취약점을 찾으세요.
GitHub로 로그인하고 1분 안에 첫 감사를 실행하세요. 무료 플랜은 신용카드가 필요 없습니다.