PT-2026-42521 · Openises+1 · Tickets

CVE-2026-48243

·

Published

2026-05-21

·

Updated

2026-05-21

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Open ISES Tickets versions prior to 3.44.2
Description The software contains a hardcoded WhitePages reverse-phone API key within the wp1.php file, which is committed to the public source repository. An attacker with read access to the source tree can extract this key to perform third-party API calls that are billed to or rate-limited against the account of the original owner.
Recommendations Update to version 3.44.2 or later.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48243

Affected Products

Tickets