Junglewise Threat Intelligence

CVE-2026-48249: Open ISES Tickets improper TLS certificate validation in mobile login

CVE-2026-48249 · Severity: medium · CVSS 5.9 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, an open-source ticketing and incident management system, contains a security flaw in its mobile login component. The software fails to verify the identity of remote servers when making secure connections, which could allow an attacker positioned on the network to intercept sensitive information. This could result in the theft of login credentials, API keys, or session data during the mobile login process.

Technical details

A vulnerability exists in Open ISES Tickets versions prior to 3.44.2 due to improper certificate validation in the 'rm/incs/mobile_login.inc.php' component. The application explicitly disables TLS verification by setting 'CURLOPT_SSL_VERIFYPEER' to false and failing to set 'CURLOPT_SSL_VERIFYHOST' during outbound HTTPS requests in the RouteMate login flow. An attacker with a man-in-the-middle (MitM) position can present a forged certificate to intercept or modify encrypted traffic, potentially capturing API keys or session tokens. This issue was addressed in version 3.44.2 by enabling certificate verification by default.

Affected products

  • Open ISES Tickets < 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-04-02: advisory: Version 3.44.2 released
  • 2026-05-21: disclosed: CVE published and NVD record created

References

Related threats