🔐 CVE Alert

CVE-2026-48210

MEDIUM 5.7

Possible information disclosure via External Interface

CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
1th

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue affects OTRS 2026.3.1

CWE CWE-200 CWE-269
Vendor otrs ag
Product otrs
Published May 31, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for otrs ag otrs

Be the first to know when new medium vulnerabilities affecting otrs ag otrs are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

OTRS AG / OTRS
2026.3.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
otrs.com: https://otrs.com/release-notes/otrs-security-advisory-2026-09/