PT-2026-42525 · Unknown · Open Ises Tickets

Published

2026-05-21

·

Updated

2026-05-21

·

CVE-2026-48247

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open ISES Tickets versions prior to 3.44.2
Description TLS certificate verification is disabled in the file incs/functions.inc.php by setting the CURLOPT SSL VERIFYPEER variable to false and failing to set CURLOPT SSL VERIFYHOST during general-purpose outbound HTTPS requests issued by shared helper functions. This allows an attacker positioned on the network path between the server and the remote endpoint to present a forged certificate to intercept, monitor, or modify requests and responses, including session-bearing data or API keys in transit.
Recommendations Update to version 3.44.2.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48247

Affected Products

Open Ises Tickets