Improper Input Validation Vulnerability in OTRS and OTRS Community Edition
CVE-2026-48188
9.1CRITICAL
What is CVE-2026-48188?
An improper input validation flaw in the database layer of OTRS and OTRS Community Edition can be exploited by an unauthenticated user to perform SQL injection attacks. This vulnerability leads to potential authentication bypass when the MySQL/MariaDB server operates in an insecure configuration that lacks proper escaping. Affected versions include multiple releases from 7.0.X to 2026.X and the Community Edition 6.0.x, as well as other products based on the OTRS framework. Users are encouraged to review their configurations and apply any recommended patches or updates.
Affected Version(s)
((OTRS)) Community Edition 6.x
OTRS 7.0.x
OTRS 7.0.x
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Special thanks to Daniel Triznafor reporting this vulnerability
