An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend
This issue affects OTRS 2026.3.1
References
| Link | Resource |
|---|---|
| https://otrs.com/release-notes/otrs-security-advisory-2026-09/ | Vendor Advisory Mitigation |
Configurations
History
15 Jun 2026, 12:47
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://otrs.com/release-notes/otrs-security-advisory-2026-09/ - Vendor Advisory, Mitigation | |
| First Time |
Otrs
Otrs otrs |
|
| CPE | cpe:2.3:a:otrs:otrs:2026.3.1:*:*:*:*:*:*:* |
31 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-31 22:16
Updated : 2026-06-15 12:47
NVD link : CVE-2026-48210
Mitre link : CVE-2026-48210
CVE.ORG link : CVE-2026-48210
JSON object : View
Products Affected
otrs
- otrs
