Executive brief
Open ISES Tickets is an open-source incident management and ticketing system. In versions prior to 3.44.2, the software fails to properly verify security certificates when communicating with other web services. This allows a well-positioned attacker to intercept or modify sensitive data, such as API keys or user session information, as it travels across the network.
Technical details
Open ISES Tickets before version 3.44.2 contains an improper certificate validation vulnerability (CWE-295) within its shared helper functions in incs/functions.inc.php. The application explicitly disables TLS verification by setting CURLOPT_SSL_VERIFYPEER to false and failing to set CURLOPT_SSL_VERIFYHOST when making outbound HTTPS requests. An attacker with man-in-the-middle (MITM) capabilities can present a forged certificate to intercept, monitor, or modify encrypted traffic. This could lead to the exposure of sensitive data, including API keys and session tokens. The issue was addressed in version 3.44.2 by enabling certificate verification by default.
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to repository
- 2026-04-02: advisory: Version 3.44.2 released
- 2026-05-21: disclosed: CVE published and NVD entry created