Executive brief
A security flaw in the OTRS service management platform allows users to view customer information they are not authorized to see. This occurs when specific group-based access controls are enabled, potentially leading to the exposure of sensitive client data to unauthorized internal or external parties. Organizations using OTRS for help desk or customer support should update to the latest version to ensure data privacy and compliance.
Technical details
An improper input validation vulnerability exists within the OTRS Customer Backend module. The flaw is specifically triggered when the 'CustomerGroupSupport' feature is enabled and in use. An authenticated attacker with low privileges can exploit this lack of validation to bypass group-based access restrictions and retrieve sensitive customer data belonging to other groups. The vulnerability is tracked as CVE-2026-48189 and has been addressed in OTRS version 2026.4.X and later. The attack requires network access and minimal user interaction.
Affected products
- OTRS AG OTRS 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, 2026.X before 2026.4.X
Timeline
- 2026-06-01: advisory: Initial disclosure of CVE-2026-48189
- 2026-06-01: disclosed