CVE-2026-38447
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs s
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 3, 2026 · Last modified: Aug 3, 2026 · CWE-331
Not enough EPSS history yet.
osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.
- github.comhttps://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38447.md
- github.comhttps://github.com/osTicket/osTicket/blob/v1.18.3/include/class.api.php#L149
- github.comhttps://github.com/osTicket/osTicket/blob/v1.18.3/include/class.misc.php
- github.comhttps://github.com/osTicket/osTicket/commit/feccb6a3a90863fd31215ee738b39762177e658c
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-15629——
———A cryptographic
weakness exists in the Omada adoption protocol where session encryption keys
used to protect communications between controllers and managed devices may be
predictable due to insufficient entropy in session key generation.
An attacker
who successfully intercepts adoption-related communications may be able to recover
session encryption keys and decrypt affected communications.9hCVE-2026-49324.2 MED0.3%
——0IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.6dCVE-2026-11403—27.6%
——8A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an active API key for this vulnerability to be exploitable.19dCVE-2026-131994.0 MED1.8%
——1EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. Additionally, the low-quality RNG seed may affect the quality of random numbers or delay booting while sufficient entropy is accumulated from other sources.28dCVE-2026-464737.5 HIG34.3%
——10Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand.
Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.12dCVE-2026-72107.5 HIG52.7%
——16`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.7d