CVE-2026-22200 is an arbitrary file read vulnerability in Enhancesoft osTicket affecting 1.18.x before 1.18.3 and 1.17.x before 1.17.7. The flaw is in the ticket PDF export workflow, where attacker-controlled rich-text HTML embedded in a ticket is insufficiently sanitized before being passed to the mPDF PDF generator. By injecting crafted PHP stream/filter expressions into ticket content, an attacker can abuse mPDF’s handling of local resources during PDF generation so that attacker-selected local files are read from the server filesystem and embedded into the exported PDF as bitmap image data. The disclosure indicates this is reachable remotely and, in common/default deployments, can be exploited by unauthenticated or low-privilege users who can create tickets and later access/export them.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
Repository purpose: proof-of-concept tooling to assess and exploit osTicket CVE-2026-22200 (unauthenticated/guest reachable PDF-based local file read via PHP filters through mPDF), and optionally chain the file-read primitive into RCE using the CNEXT technique (CVE-2024-2961). Structure (10 files): - README.md: describes CVE-2026-22200 file read and chaining to CNEXT RCE; references Horizon3 blog. - check.py: unauthenticated vulnerability/exploitability checker. It probes osTicket endpoints (login.php, account.php, open.php, tickets.php) to infer patch status (notably via username format pre-validation returning “Invalid User Id” when patched) and whether guest workflows are enabled. - osticket_ticket_payload_gen.py: generates osTicket-specific HTML payloads that embed php://filter chains into CSS list-style-image URLs. Includes URL-encoding tricks (forced uppercase encoding, special separator) to bypass osTicket/htmLawed sanitization and mPDF quirks. Supports reading arbitrary files and optional base64/zlib transformations. - extract_pdf_images.py: post-exploitation helper to extract and decode exfiltrated file contents embedded in PDF bitmap images (best-effort base64 decode and raw zlib inflate). - cnext_exploit_payload_gen.py: offline generator for a CNEXT filter-chain payload. It consumes exfiltrated /proc/self/maps and a matching libc to compute addresses and prints a crafted php://filter path intended to achieve command execution when delivered through the file-read primitive. - try_download_libc.py: helper to recover full libc from libc.rip using a build-id extracted from a partial libc blob exfiltrated via the PDF channel; also attempts to print the libc version string. - osticket_access_bruteforce.py: auxiliary script to enumerate valid ticket-number/email combinations by requesting access links via login.php (CSRF-aware, threaded). - osticket_registered_user_enum.py: auxiliary user enumeration by attempting account registration via account.php and checking for “Email already registered”. - osticket_forge_access_link.py: auxiliary tool to craft a direct ticket view link (view.php?t=...&e=...&a=md5(...)) if the attacker knows/guesses the secret salt. - requirements.txt: dependencies (PyMuPDF, pillow, requests, pwntools, ten). Overall capabilities: end-to-end workflow for (1) checking patch/exploitability, (2) generating file-read payloads, (3) extracting exfiltrated data from PDFs, and (4) preparing a chained CNEXT payload for RCE given sufficient memory-layout/libc information.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 2026-era vulnerability referenced only as having a custom Nuclei scanning template present in the exposed operator files.
Unknown
An osTicket vulnerability where unauthenticated attackers can inject malicious PHP expressions into ticket content and leverage PDF export to exfiltrate data and/or achieve code execution on unpatched servers.
Unknown
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.