PatchSiren cyber security CVE debrief
CVE-2026-35007 openises CVE debrief
CVE-2026-35007 describes a reflected cross-site scripting issue in Open ISES Tickets before version 3.44.2. The flaw is in single_unit.php, where an unsanitized id GET parameter is passed into an HTML attribute. An authenticated attacker can craft a malicious URL so that JavaScript executes when a victim opens the link. The CVE was published on 2026-05-20 and no KEV entry is provided in the supplied corpus.
- Vendor
- openises
- Product
- tickets
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-23
Who should care
Administrators and operators running Open ISES Tickets versions earlier than 3.44.2 should treat this as relevant, especially if authenticated users can share or open application links. Security teams responsible for web application hardening and input/output encoding should also review affected deployments.
Technical summary
The issue is a reflected XSS vulnerability classified as CWE-79. In single_unit.php, the id parameter from the query string is not sanitized before being placed into an HTML attribute context. Because the payload is reflected in the response, an attacker with authentication can lure a victim into visiting a crafted URL that causes attacker-controlled JavaScript to run in the victim’s browser. The supplied source references point to a fixing commit and the v3.44.2 release tag.
Defensive priority
Medium
Recommended defensive actions
- Upgrade Open ISES Tickets to version 3.44.2 or later.
- Review single_unit.php and any related request handlers for proper output encoding in HTML attribute context.
- Validate and constrain the id parameter server-side before use.
- Audit authenticated workflows that accept or display user-influenced URLs to reduce phishing-style XSS delivery paths.
- Check application logging and security monitoring for suspicious links targeting single_unit.php.
- Confirm the product attribution and affected version range against the vendor release and advisory references.
Evidence notes
The supplied corpus ties this CVE to Open ISES Tickets and cites three references: a GitHub commit that appears to fix the issue, the v3.44.2 release tag, and a VulnCheck advisory. The NVD record shows the CVE as published on 2026-05-20 with vulnStatus Received. The provided metadata marks vendor confidence as low and needs review, so the product attribution should be validated against the linked sources before broad reporting.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35007 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35007
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35007 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35007
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a9f2dbff
-
Source reference
Unverified legacy reference
URL: https://github.com/openises/tickets/releases/tag/v3.44.2
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-single-unit-php-id-parameter
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.