Junglewise Threat Intelligence

CVE-2026-48208: OTRS improper neutralization of SVG content in ticket rendering

CVE-2026-48208 · Severity: medium · CVSS 6.5 · Published 2026-06-01

Technologies: OTRS AG OTRS Community Edition. Vendors: OTRS AG.

Executive brief

OTRS is a service management and ticketing platform used for customer support and IT service management. A vulnerability in how the system handles email attachments allows attackers to send specially crafted images (SVG files) that crash the web browser of any agent or customer who opens the ticket. This results in a denial of service, preventing staff from accessing or processing support requests.

Technical details

A vulnerability exists in the ticket article rendering component of OTRS due to improper neutralization of active SVG content (CWE-791). An unauthenticated attacker can send a specially crafted SVG payload via email. When an agent or customer views the affected ticket, the payload triggers uncontrolled resource consumption (CWE-400) within the browser, leading to a denial of service. Notably, the exploit does not require JavaScript execution and bypasses standard Content Security Policy (CSP) protections. The issue is fixed in OTRS version 2026.4.X.

Affected products

  • OTRS AG OTRS 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, 2026.X before 2026.4.X
  • OTRS AG OTRS Community Edition 6.x and earlier

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References

Related threats