Incorrect Permission Handling in OTRS Affects Multiple Versions
CVE-2026-48190

3.5LOW

Key Information:

Vendor

Otrs Ag

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-48190?

The OTRS software includes a vulnerability that arises from incorrect management of permissions within its External Interface and the ConfigItem List module. This flaw can potentially allow an authenticated customer to access confidential configuration item (CI) information from the system. This issue is particularly relevant when the Configuration Management Database (CMDB) feature is enabled and the CustomerGroupSupport functionality is in use. Affected versions span from 7.0.X up to 2026.X, specifically those prior to 2026.4.X.

Affected Version(s)

OTRS 7.0.x

OTRS 8.0.x

OTRS 2023.x

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.