MEDIUM
Open ISES Tickets < 3.44.2 Hardcoded WhitePages API Key in wp1.php
Published May 21, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.38%
Description
Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with read access to the source tree can extract the key and use it to make third-party API calls billed to or rate-limited against the original owner's WhitePages account.
Affected products
-
Affected
- ≥ 0, < 3.44.2
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31325 Advisory
- https://github.com/openises/tickets/commit/ecfeb406a016766cae81c749e14b5145a9f2dbff patch
- https://github.com/openises/tickets/releases/tag/v3.44.2 release-notes
- https://www.vulncheck.com/advisories/open-ises-tickets-hardcoded-whitepages-api-key-in-wp1-php third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 21, 2026
Updated Jul 28, 2026
Reserved May 21, 2026
Link CVE-2026-48243
CISA Vulnrichment
Updated May 21, 2026
Red Hat
No data
GitHub
No data