Junglewise Threat Intelligence

CVE-2026-48248: Open ISES Tickets improper TLS certificate validation in login component

CVE-2026-48248 · Severity: medium · CVSS 5.9 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, an open-source ticketing system, fails to properly verify security certificates when communicating with other servers during the login process. This flaw allows a sophisticated attacker positioned on the network to intercept sensitive information, such as login credentials or API keys, by impersonating a trusted server. Organizations using this software should upgrade to version 3.44.2 or later to ensure their data remains encrypted and secure during transit.

Technical details

Open ISES Tickets before version 3.44.2 contains an improper certificate validation vulnerability (CWE-295) within 'incs/login.inc.php'. The application explicitly disables TLS verification by setting 'CURLOPT_SSL_VERIFYPEER' to false and failing to set 'CURLOPT_SSL_VERIFYHOST' during outbound HTTPS requests in the authentication flow. A man-in-the-middle (MITM) attacker positioned between the server and the remote endpoint can present a forged certificate to intercept, monitor, or modify traffic. This can lead to the exposure of API keys and session-bearing data. The issue is resolved in version 3.44.2.

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-21: disclosed: CVE-2026-48248 published

References

Related threats