PatchSiren cyber security CVE debrief
CVE-2026-48237 Open ISES CVE debrief
CVE-2026-48237 affects Open ISES Tickets before version 3.44.2 and was published on 2026-05-21. The vulnerability is a SQL injection in message.php involving the frm_ticket_id and frm_resp_id POST parameters. Because those values are concatenated into WHERE clauses without sanitization, an authenticated attacker can alter query behavior and potentially read, modify, or destroy database contents. A fix is referenced in the upstream 3.44.2 release and a corresponding commit.
- Vendor
- Open ISES
- Product
- Tickets
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-07-23
Who should care
Administrators and developers responsible for Open ISES Tickets deployments before 3.44.2 should treat this as important. Security teams should also care if the application is reachable by authenticated users who can submit ticket-related requests.
Technical summary
The issue is classified as CWE-89 (SQL Injection). According to the source corpus, message.php uses frm_ticket_id and frm_resp_id in SELECT/UPDATE WHERE clauses without sanitization, allowing query manipulation. The supplied record also lists CVSS 4.0 vector elements indicating network exposure, low attack complexity, and required privileges, with confidentiality impact high and integrity impact low.
Defensive priority
High. Remediate promptly by upgrading to the fixed release and reviewing any exposed authenticated workflows that interact with message.php or related ticket-handling code.
Recommended defensive actions
- Upgrade Open ISES Tickets to version 3.44.2 or later.
- Review the upstream fix in the referenced commit to understand the code path change.
- Audit message.php and related request handlers for parameterized queries and input validation.
- Check logs for unusual ticket-message requests that may indicate query manipulation attempts.
- Restrict authenticated access to the minimum necessary users until patching is complete.
Evidence notes
This debrief is based only on the supplied CVE record and referenced upstream materials. The CVE was published and last modified on 2026-05-21. The source corpus identifies the weakness as CWE-89 and links a fix to the openises/tickets 3.44.2 release and upstream commit. Vendor metadata in the supplied item is low-confidence and marked for review, so the product mapping here follows the reference corpus rather than the vendor field alone.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48237 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48237
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48237 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48237
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a9f2dbff
-
Source reference
Unverified legacy reference
URL: https://github.com/openises/tickets/releases/tag/v3.44.2
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/open-ises-tickets-sql-injection-via-message-php-frm-ticket-id-and-frm-resp-id-parameters
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.