Junglewise Threat Intelligence

CVE-2026-48209: OTRS reflected cross-site scripting in ticket handling

CVE-2026-48209 · Severity: high · CVSS 7.1 · Published 2026-06-01

Technologies: OTRS AG OTRS Community Edition. Vendors: OTRS AG.

Executive brief

OTRS is a service management and ticketing platform used by organizations to manage customer support and IT services. A security vulnerability in how the system handles ticket requests allows attackers to trick authorized staff into clicking a malicious link. If successful, the attacker can execute unauthorized commands or access data within the staff member's active session, potentially compromising sensitive support tickets and customer information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in OTRS 7.0.x and OTRS Community Edition 6.x and earlier due to improper neutralization of user-controllable input. The flaw is located within the ticket handling component, specifically affecting request parameters associated with ticket actions. An attacker can craft a malicious URL containing JavaScript; when an authenticated agent visits this link, the script executes within the context of their session. This can lead to unauthorized actions being performed on behalf of the agent or the theft of session tokens. While the CVSS vector indicates no privileges are required (PR:N), the attack relies on user interaction (UI:R) from an authenticated agent to be successful.

Affected products

  • OTRS AG OTRS 7.0.x
  • OTRS AG OTRS Community Edition 6.x and earlier

Timeline

  • 2026-06-01: disclosed: Initial publication of CVE-2026-48209
  • 2026-06-01: advisory: OTRS AG security advisory 2026-08 published

References

Related threats