TLS Certificate Verification Vulnerability in Open ISES Tickets by OpenISES
CVE-2026-48249
8.2HIGH
What is CVE-2026-48249?
The Open ISES Tickets application prior to version 3.44.2 contains a vulnerability that disables TLS certificate verification by incorrectly setting parameters in the mobile login flow. This flaw allows a malicious actor positioned in the network path to exploit the lack of verification by presenting a forged certificate. Consequently, an attacker can intercept, monitor, or modify requests and responses, potentially exposing sensitive information such as API keys and session data during secure transactions.
Affected Version(s)
Tickets 0 < 3.44.2
