PT-2026-45213 · Otrs · Otrs
CVE-2026-48210
·
Published
2026-05-31
·
Updated
2026-05-31
CVSS v3.1
5.7
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OTRS version 2026.3.1
Description
An improper default configuration causes ticket article forwarding actions to enforce the "Is visible for customer" flag by default. This prevents users from disabling the flag via the user interface, resulting in the unintended exposure of internal ticket information to the External Frontend.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Otrs