PT-2026-45264 · Unknown+1 · Otrs Community Edition+1
Daniel Triznafor
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-48208
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OTRS versions 7.0.X
OTRS versions 8.0.X
OTRS versions 2023.X
OTRS versions 2024.X
OTRS versions 2025.X
OTRS versions prior to 2026.4.X
OTRS Community Edition versions 6.x and earlier
Description
Improper neutralization of active SVG content in ticket article rendering allows attackers to inject specially crafted SVG payloads through email content. This leads to browser-side resource exhaustion and denial of service when an agent or customer opens the affected tickets. The issue does not require JavaScript execution and is not mitigated by the configured Content Security Policy (CSP), which is a security layer that helps detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks.
Recommendations
Update OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, and 2025.X to a version containing the fix.
Update OTRS version 2026.X to version 2026.4.X or later.
Update OTRS Community Edition version 6.x and earlier to a patched version.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Otrs
Otrs Community Edition