As cited
Copy frozen at (site build).
vulnerabilities
Ticket to Shell: Exploiting PHP Filters and CNEXT in osTicket (CVE-2026-22200)
CVE-2026-22200 is a vulnerability in osTicket that enables unauthenticated attackers to read arbitrary files from affected servers. An attacker can inject a malicious PHP filter chain expression into a support ticket, then export the ticket to PDF format to extract sensitive data embedded as images within the document.
Why it matters: Organizations running osTicket must patch immediately, as the vulnerability allows file exfiltration without authentication and could expose configuration files, credentials, or other sensitive data stored on the server.
- Source published
- First seen by Cybersecurity Tracker