Junglewise Threat Intelligence

CVE-2026-48244: Open ISES Tickets hardcoded Google Maps API key in settings.inc.php

CVE-2026-48244 · Severity: medium · CVSS 5.3 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, a support ticketing system, contained a hardcoded Google Maps API key within its public source code. An unauthorized individual could extract this key and use it to make map-related requests that are billed to the original owner's Google Cloud account. This could lead to unexpected financial charges and the exhaustion of the organization's Google Maps service quota.

Technical details

A hardcoded Google Maps API key was discovered in the 'settings.inc.php' file of Open ISES Tickets versions prior to 3.44.2. Because this file was committed to a public GitHub repository, the credential is accessible to any user with read access to the source code. An attacker can extract this key and utilize it to authenticate requests to the Google Maps Platform. These unauthorized requests are billed against the project owner's Google Cloud account, potentially leading to financial loss or service denial if usage limits are reached. The issue was addressed in version 3.44.2 by removing the hardcoded secret.

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository.
  • 2026-04-02: advisory: Version 3.44.2 released.
  • 2026-05-21: disclosed: CVE published.

References

Related threats