PT-2026-45261 · Otrs · Otrs
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-48189
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS versions 7.0.x
OTRS versions 8.0.x
OTRS versions 2023.x
OTRS versions 2024.x
OTRS versions 2025.x
OTRS versions prior to 2026.4.x
Description
Improper input validation in the Customer Backend module allows unauthorized access to customer information restricted to other groups. This issue occurs when the specific feature is enabled and
CustomerGroupSupport is utilized.Recommendations
Update OTRS versions 7.0.x, 8.0.x, 2023.x, 2024.x, and 2025.x to a version containing the fix.
Update OTRS versions prior to 2026.4.x to version 2026.4.x or later.
As a temporary mitigation, disable the Customer Backend feature or restrict the use of
CustomerGroupSupport.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otrs