An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected.
This issue affects OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X
References
| Link | Resource |
|---|---|
| https://otrs.com/release-notes/otrs-security-advisory-2026-03/ | Vendor Advisory |
Configurations
History
15 Jun 2026, 12:45
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://otrs.com/release-notes/otrs-security-advisory-2026-03/ - Vendor Advisory | |
| CPE | cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:* | |
| First Time |
Otrs
Otrs otrs |
01 Jun 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-01 04:16
Updated : 2026-06-15 12:45
NVD link : CVE-2026-48189
Mitre link : CVE-2026-48189
CVE.ORG link : CVE-2026-48189
JSON object : View
Products Affected
otrs
- otrs
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
