CVE-2026-6060
Possible DoS via SQL Box
CVSS Score
4.5
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS:ย * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.3.X
| CWE | CWE-400 CWE-770 |
| Vendor | otrs ag |
| Product | otrs |
| Published | Apr 20, 2026 |
| Last Updated | Apr 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for otrs ag otrs
Be the first to know when new medium vulnerabilities affecting otrs ag otrs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
OTRS AG / OTRS
7.0.x 8.0.x 2023.x 2024.x 2025.x 2026.x โค 2026.2.x
References
Credits
๐ Special thanks to Matthias Terlinde for reporting this vulnerability