PT-2026-45261 · Otrs · Otrs

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-48189

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OTRS versions 7.0.x OTRS versions 8.0.x OTRS versions 2023.x OTRS versions 2024.x OTRS versions 2025.x OTRS versions prior to 2026.4.x
Description Improper input validation in the Customer Backend module allows unauthorized access to customer information restricted to other groups. This issue occurs when the specific feature is enabled and CustomerGroupSupport is utilized.
Recommendations Update OTRS versions 7.0.x, 8.0.x, 2023.x, 2024.x, and 2025.x to a version containing the fix. Update OTRS versions prior to 2026.4.x to version 2026.4.x or later. As a temporary mitigation, disable the Customer Backend feature or restrict the use of CustomerGroupSupport.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48189

Affected Products

Otrs