CVE-2026-48210
Possible information disclosure via External Interface
CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
1th
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue affects OTRS 2026.3.1
| CWE | CWE-200 CWE-269 |
| Vendor | otrs ag |
| Product | otrs |
| Published | May 31, 2026 |
| Last Updated | Jun 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for otrs ag otrs
Be the first to know when new medium vulnerabilities affecting otrs ag otrs are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
OTRS AG / OTRS
2026.3.1