PT-2026-45213 · Otrs · Otrs

CVE-2026-48210

·

Published

2026-05-31

·

Updated

2026-05-31

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OTRS version 2026.3.1
Description An improper default configuration causes ticket article forwarding actions to enforce the "Is visible for customer" flag by default. This prevents users from disabling the flag via the user interface, resulting in the unintended exposure of internal ticket information to the External Frontend.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48210

Affected Products

Otrs