Junglewise Threat Intelligence

CVE-2026-48226: Open ISES Tickets Reflected XSS in os_watch.php

CVE-2026-48226 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, an open-source ticketing and incident management system, contains a security flaw in its 'os_watch.php' component. An authenticated attacker can trick a user into executing malicious scripts within their browser. This could lead to unauthorized actions being performed on behalf of the user, such as data theft or session hijacking.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in 'os_watch.php', where the 'ref' and 'mode_orig' POST parameters are not properly sanitized before being rendered into the value attributes of hidden HTML form inputs. An authenticated attacker can exploit this by crafting a malicious request that, when processed by a victim's browser, executes arbitrary JavaScript in the context of the victim's session. This vulnerability was addressed in version 3.44.2 by implementing input sanitization using htmlspecialchars() with ENT_QUOTES.

Affected products

  • Open ISES Tickets < 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-21: disclosed: CVE-2026-48226 published

References

Related threats