Permission Handling Flaw in OTRS and STORM Modules
CVE-2026-48191
3.5LOW
What is CVE-2026-48191?
An improper handling of permissions in OTRS and STORM modules can lead to unintended exposure of sensitive information, including the number of affected Configuration Items (CIs) and Service Level Agreements (SLAs). This vulnerability enables unauthorized users to gain insights into these elements without having the necessary access privileges, posing a significant risk to the confidentiality of critical service information.
Affected Version(s)
OTRS 8.0.x
OTRS 2023.x
OTRS 2024.x
