Junglewise Threat Intelligence

CVE-2026-48187: OTRS uncontrolled resource consumption in e-mail handling

CVE-2026-48187 · Severity: medium · CVSS 5.7 · Published 2026-06-01

Technologies: OTRS AG OTRS Community Edition. Vendors: OTRS AG.

Executive brief

OTRS is a service management and ticketing platform used for customer support and IT service management. A vulnerability in how the system handles incoming emails allows for excessive resource consumption, which can cause the web server to crash. This could lead to a service outage, preventing staff from accessing tickets or responding to customer inquiries.

Technical details

A resource exhaustion vulnerability (CWE-400/CWE-770) exists in the email handling component of OTRS. The system fails to properly limit or throttle resource allocation during the processing of emails, allowing an attacker to trigger excessive memory or CPU usage. Exploitation requires network reachability and low-privileged authentication, along with minimal user interaction. Successful exploitation results in the abortion of the web server process, leading to a denial-of-service. The issue is fixed in version 2026.4.X and later.

Affected products

  • OTRS AG OTRS 8.0.X, 2023.X, 2024.X, 2025.X, 2026.X before 2026.4.X
  • OTRS AG OTRS Community Edition 6.x, 7.x

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References

Related threats