Junglewise Threat Intelligence

CVE-2026-48210: OTRS improper default configuration in ticket article forwarding

CVE-2026-48210 · Severity: medium · CVSS 5.7 · Published 2026-05-31

Vendors: OTRS AG.

Executive brief

OTRS, a popular service management and ticketing platform, contains a configuration error that may expose private internal communications to external customers. When staff members forward ticket articles, the system incorrectly forces these messages to be visible on the customer-facing portal without allowing staff to hide them. This could lead to the accidental disclosure of sensitive internal notes, private business logic, or confidential employee discussions to unauthorized external parties.

Technical details

A configuration flaw in OTRS version 2026.3.1 leads to improper privilege management and information exposure (CWE-269, CWE-200). The vulnerability is rooted in the ticket article forwarding component, where the 'Is visible for customer' flag is enforced by default and cannot be toggled off by the user through the standard interface. An authenticated internal user (agent) performing routine forwarding actions would inadvertently publish internal data to the External Frontend. This allows any customer with access to the ticket to view internal-only communications. The issue is categorized as medium severity with a CVSS score of 5.7, primarily impacting confidentiality.

Affected products

  • OTRS AG OTRS 2026.3.1

Timeline

  • 2026-05-31: disclosed
  • 2026-05-31: advisory

References