CVE-2026-48208

An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP). This issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*

History

22 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Una neutralización inadecuada de contenido SVG activo en la representación de artículos de tickets de OTRS o ((OTRS)) Community Edition permite a los atacantes inyectar cargas útiles SVG especialmente diseñadas a través del contenido del correo electrónico, lo que lleva al agotamiento de recursos del lado del navegador y a la denegación de servicio cuando los tickets afectados son abiertos por un agente o cliente. El problema puede ser explotado sin ejecución de JavaScript y no es mitigado por la Política de Seguridad de Contenido (CSP) configurada. Este problema afecta a OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X antes de 2026.4.X Tenga en cuenta que ((OTRS)) Community Edition 6.x y versiones anteriores son vulnerables. Los productos basados en ((OTRS)) Community Edition también son muy propensos a ser afectados.

15 Jun 2026, 12:39

Type Values Removed Values Added
First Time Otrs
Otrs otrs
CPE cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*
References () https://otrs.com/release-notes/otrs-security-advisory-2026-07/ - () https://otrs.com/release-notes/otrs-security-advisory-2026-07/ - Vendor Advisory

01 Jun 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 04:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-48208

Mitre link : CVE-2026-48208

CVE.ORG link : CVE-2026-48208


JSON object : View

Products Affected

otrs

  • otrs
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-791

Incomplete Filtering of Special Elements