Executive brief
A critical vulnerability has been identified in OTRS, a widely used service management and ticketing platform. An attacker can bypass the system's login requirements to gain unauthorized access to sensitive data and administrative functions. This flaw specifically impacts organizations using MySQL or MariaDB databases configured with a specific non-standard setting (NO_BACKSLASH_ESCAPES).
Technical details
An improper input validation vulnerability exists in the database layer module of OTRS and OTRS Community Edition. The flaw allows for unauthenticated SQL injection, which can be leveraged to achieve a full authentication bypass. This vulnerability is conditional; it only affects systems where the underlying MySQL or MariaDB database is configured with the 'NO_BACKSLASH_ESCAPES' SQL mode. Attackers can exploit this over the network without any prior credentials or user interaction. Users are advised to upgrade to OTRS 2026.4.X or later to mitigate the risk.
Affected products
- OTRS AG OTRS 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, 2026.X before 2026.4.X
- OTRS AG OTRS Community Edition 6.0.x
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory