A vulnerability has been found in osTicket 1.18.2 and classified as problematic. Impacted is an unknown function of the file /pwreset.php. This manipulation causes information disclosure.

This vulnerability is handled as CVE-2026-26895. The attack can be initiated remotely. There is not any exploit available.