CVE-2026-48245

Severity CVSS v4.0:
MEDIUM
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
21/05/2026
Last modified:
21/05/2026

Description

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can be extracted by anyone with read access to the source and used to make Google Maps Platform requests billed against the original owner's Google Cloud project.