Junglewise Threat Intelligence

CVE-2026-48191: OTRS STORM incorrect permission handling in Document Search Article Meta Filters

CVE-2026-48191 · Severity: low · CVSS 3.5 · Published 2026-06-01

Vendors: OTRS AG.

Executive brief

OTRS is a service management suite used by organizations to manage customer support and IT operations. A security flaw in its search and filtering modules allows users to see metadata about internal assets, service level agreements (SLAs), and services they are not authorized to access. While this does not grant full access to the records, it exposes sensitive operational statistics and configuration details to unauthorized personnel.

Technical details

An incorrect permission handling vulnerability (CWE-276) exists in the Document Search Article Meta Filters modules of OTRS and STORM. The flaw allows an authenticated attacker with low privileges to gain information about the number of affected Configuration Items (CIs), Service Level Agreements (SLAs), and services without having the necessary access rights to those objects. The attack requires network access and minimal user interaction. The issue is resolved in version 2026.4.X and later.

Affected products

  • OTRS AG OTRS with STORM modules 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, 2026.X before 2026.4.X

Timeline

  • 2026-06-01: advisory: Initial advisory published by OTRS AG
  • 2026-06-01: disclosed: CVE-2026-48191 published to NVD

References