Permission Handling Flaw in OTRS and STORM Modules
CVE-2026-48191

3.5LOW

Key Information:

Vendor

Otrs Ag

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-48191?

An improper handling of permissions in OTRS and STORM modules can lead to unintended exposure of sensitive information, including the number of affected Configuration Items (CIs) and Service Level Agreements (SLAs). This vulnerability enables unauthorized users to gain insights into these elements without having the necessary access privileges, posing a significant risk to the confidentiality of critical service information.

Affected Version(s)

OTRS 8.0.x

OTRS 2023.x

OTRS 2024.x

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.