PT-2026-45213 · Otrs Ag · Otrs

Published

2026-05-31

·

Updated

2026-05-31

·

CVE-2026-48210

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend
This issue affects OTRS 2026.3.1

Fix

Improper Privilege Management

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-48210

Affected Products

Otrs