Executive brief
OTRS is a service management and ticketing platform used by organizations to manage customer support and IT services. A security vulnerability in how the system handles ticket requests allows attackers to trick authorized staff into clicking a malicious link. If successful, the attacker can execute unauthorized commands or access data within the staff member's active session, potentially compromising sensitive support tickets and customer information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in OTRS 7.0.x and OTRS Community Edition 6.x and earlier due to improper neutralization of user-controllable input. The flaw is located within the ticket handling component, specifically affecting request parameters associated with ticket actions. An attacker can craft a malicious URL containing JavaScript; when an authenticated agent visits this link, the script executes within the context of their session. This can lead to unauthorized actions being performed on behalf of the agent or the theft of session tokens. While the CVSS vector indicates no privileges are required (PR:N), the attack relies on user interaction (UI:R) from an authenticated agent to be successful.
Affected products
- OTRS AG OTRS 7.0.x
- OTRS AG OTRS Community Edition 6.x and earlier
Timeline
- 2026-06-01: disclosed: Initial publication of CVE-2026-48209
- 2026-06-01: advisory: OTRS AG security advisory 2026-08 published