PatchSiren cyber security CVE debrief
CVE-2026-35011 openises CVE debrief
CVE-2026-35011 is a reflected cross-site scripting issue in Open ISES Tickets before version 3.44.2. According to the provided advisory and NVD record, the opena.php endpoint can reflect an unsanitized frm_call GET parameter into page output, allowing JavaScript injection in a victim’s browser when a crafted URL is visited. NVD lists the issue as CVSS 5.1/Medium, and the referenced fix is included in the 3.44.2 release.
- Vendor
- openises
- Product
- tickets
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-23
Who should care
Organizations running Open ISES Tickets versions prior to 3.44.2, especially teams with authenticated users who can access opena.php or share URLs inside the application. Security teams should also care if the application is used in a browser session where reflected content could execute in a trusted user’s context.
Technical summary
The vulnerability is a reflected XSS (CWE-79) in opena.php. The frm_call GET parameter is described as being passed into page output without proper sanitization, which can let an attacker supply JavaScript that executes in the browser of a user who opens the malicious link. The source corpus ties remediation to the v3.44.2 release and a corresponding repository commit. The provided NVD vector and the advisory should be treated as the authoritative basis for scope and severity.
Defensive priority
Medium. Prioritize if Open ISES Tickets is internet-facing, used by many internal users, or reachable by users with elevated trust in the application, because successful XSS can steal session data, perform actions in the user’s context, or support phishing within the app.
Recommended defensive actions
- Upgrade Open ISES Tickets to version 3.44.2 or later.
- Review opena.php and any related request handling for output encoding and input validation on frm_call.
- Treat user-supplied query parameters as untrusted and ensure they are safely escaped before rendering in HTML or script contexts.
- If immediate upgrade is not possible, consider restricting access to affected interfaces and monitoring for suspicious URLs containing unexpected frm_call values.
- Validate that security controls such as CSP and session protections are in place, while recognizing they do not replace the code fix.
Evidence notes
Supported by the NVD CVE record for CVE-2026-35011 and the VulnCheck advisory references included in the source corpus. The corpus cites the Open ISES Tickets repository commit ecfeb406a016766cae81c749e14b5145a9f2dbff and the v3.44.2 release tag as the remediation references. Published and modified timestamps in the supplied record are 2026-05-20T20:16:38.350Z.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35011 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35011
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35011 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35011
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a9f2dbff
-
Source reference
Unverified legacy reference
URL: https://github.com/openises/tickets/releases/tag/v3.44.2
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/open-ises-tickets-reflected-xss-via-opena-php-frm-call-parameter
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.