PatchSiren cyber security CVE debrief
CVE-2026-48245 Open ISES CVE debrief
CVE-2026-48245 describes a secret exposure issue in Open ISES Tickets before version 3.44.2. A Google Maps API key was hardcoded in tables.php and committed to the public source repository, making it readable by anyone with access to the code. Because the key could be reused to make Google Maps Platform requests charged to the original Google Cloud project, the issue creates both abuse and billing risk. The recorded CVSS score is 6.9 (Medium), and the weakness mapping is CWE-798, use of hard-coded credentials. The practical risk is not remote code execution; it is unauthorized use of a live API credential, potential quota exhaustion, and unexpected charges until the key is revoked or restricted.
- Vendor
- Open ISES
- Product
- Tickets
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-21
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-21
- Advisory updated
- 2026-07-23
Who should care
Maintainers and operators of Open ISES Tickets deployments, anyone who cloned or mirrored the affected repository, and Google Cloud administrators responsible for the exposed Maps API key and billing account.
Technical summary
According to the supplied disclosure, versions of Open ISES Tickets before 3.44.2 included a hardcoded Google Maps API key in tables.php and committed it to the public repository. That makes the credential trivially recoverable from source history. The impact is abuse of Google Maps Platform API access under the original project, with likely billing and quota consequences rather than direct system compromise. The issue is classified as CWE-798.
Defensive priority
High
Recommended defensive actions
- Upgrade Open ISES Tickets to v3.44.2 or later.
- Treat the exposed Google Maps API key as compromised and revoke or rotate it in Google Cloud.
- Check the Google Cloud project for unauthorized Maps API usage, quota spikes, or unexpected billing.
- Apply API key restrictions and usage limits so any replacement key is locked to the minimum required services and referrers.
- Review repository history and deployment artifacts for any additional hardcoded secrets.
- Set up billing alerts and API usage monitoring to catch future misuse quickly.
Evidence notes
This debrief is based only on the supplied CVE record and the referenced VulnCheck disclosure materials. The source corpus states that the affected code was committed publicly, that the issue was fixed in release v3.44.2, and that the weakness is CWE-798. The NVD record for this CVE is marked Deferred in the supplied metadata, so the product naming here follows the provided source context rather than an independently validated vendor profile.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48245 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48245
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48245 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48245
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a9f2dbff
-
Source reference
Unverified legacy reference
URL: https://github.com/openises/tickets/releases/tag/v3.44.2
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/open-ises-tickets-hardcoded-google-maps-api-key-in-tables-php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.