Executive brief
OTRS is a service management suite used by organizations to manage customer support and IT operations. A security flaw in its search and filtering modules allows users to see metadata about internal assets, service level agreements (SLAs), and services they are not authorized to access. While this does not grant full access to the records, it exposes sensitive operational statistics and configuration details to unauthorized personnel.
Technical details
An incorrect permission handling vulnerability (CWE-276) exists in the Document Search Article Meta Filters modules of OTRS and STORM. The flaw allows an authenticated attacker with low privileges to gain information about the number of affected Configuration Items (CIs), Service Level Agreements (SLAs), and services without having the necessary access rights to those objects. The attack requires network access and minimal user interaction. The issue is resolved in version 2026.4.X and later.
Affected products
- OTRS AG OTRS with STORM modules 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, 2026.X before 2026.4.X
Timeline
- 2026-06-01: advisory: Initial advisory published by OTRS AG
- 2026-06-01: disclosed: CVE-2026-48191 published to NVD