Junglewise Threat Intelligence

CVE-2026-48190: OTRS incorrect permissions in External Interface and ConfigItem List module

CVE-2026-48190 · Severity: low · CVSS 3.5 · Published 2026-06-01

Vendors: OTRS AG.

Executive brief

OTRS is a service management and ticketing platform used for customer support and IT service management. A security flaw in the customer-facing interface allows authenticated customers to view internal configuration item (CI) information they should not have access to. This could lead to the exposure of sensitive technical details about the organization's IT infrastructure. This issue only affects systems where the Configuration Management Database (CMDB) and Customer Group Support features are enabled.

Technical details

A vulnerability classified as Incorrect Default Permissions (CWE-276) exists in the OTRS External Interface and the ConfigItem List module. The flaw allows an authenticated customer user to bypass intended access restrictions and query the system for Configuration Item (CI) information from the CMDB. For a system to be vulnerable, the CMDB must be enabled and 'CustomerGroupSupport' must be active. The attack requires network access and low-level customer authentication, though the CVSS vector suggests some level of user interaction may be involved. The issue is addressed in OTRS version 2026.4.X.

Affected products

  • OTRS AG OTRS 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, 2026.X before 2026.4.X

Timeline

  • 2026-06-01: disclosed: Initial publication of the CVE record
  • 2026-06-01: advisory: NVD record published based on OTRS AG advisory

References

Related threats