PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48213 Open ISES CVE debrief

CVE-2026-48213 is a reflected cross-site scripting issue in Open ISES Tickets prior to version 3.44.2. The problem is in add.php, where an unsanitized ticket_id POST value is inserted into an HTML form input value attribute. An authenticated attacker can send a crafted request so that malicious JavaScript executes in the victim’s browser when the response is rendered.

Vendor
Open ISES
Product
Tickets
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-21
Original CVE updated
2026-07-23
Advisory published
2026-05-21
Advisory updated
2026-07-23

Who should care

Administrators and security teams running Open ISES Tickets, especially deployments that expose add.php to authenticated users. Any organization that allows lower-trust or broad internal users to interact with ticket creation workflows should treat this as a browser-side injection risk.

Technical summary

The vulnerable flow reflects user-controlled ticket_id data into HTML without proper sanitization or encoding. Because the value lands in an attribute context, a crafted payload can break out of the intended value and execute script in the browser. The issue is tracked as CWE-79 and is fixed in Open ISES Tickets v3.44.2 per the referenced release and commit.

Defensive priority

Medium. The issue requires authentication and user interaction, but successful exploitation can execute script in a victim session and enable phishing, session abuse, or unauthorized actions in the application context.

Recommended defensive actions

  • Upgrade Open ISES Tickets to version 3.44.2 or later.
  • Review any backports, forks, or customizations to confirm the ticket_id value is HTML-escaped before rendering in add.php.
  • Validate that other request parameters are not reflected into HTML attribute contexts without encoding.
  • Use layered browser defenses where practical, such as a restrictive Content Security Policy and secure cookie settings.
  • If immediate upgrade is not possible, limit access to the affected authenticated workflow to the smallest practical user set.

Evidence notes

The NVD record for CVE-2026-48213 cites a VulnCheck disclosure and references a fixing commit plus the v3.44.2 release tag. The CVE description states the flaw affects Open ISES Tickets before 3.44.2 and that the vulnerable sink is add.php with the ticket_id POST parameter. NVD currently marks the vulnerability status as Deferred in the provided source item.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48213 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48213

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48213 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48213

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.