An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled andĀ CustomerGroupSupportĀ has to be used to be affected.
This issue affects OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X
References
| Link | Resource |
|---|---|
| https://otrs.com/release-notes/otrs-security-advisory-2026-03/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-01 04:16
Updated : 2026-07-22 07:10
NVD link : CVE-2026-48189
Mitre link : CVE-2026-48189
CVE.ORG link : CVE-2026-48189
JSON object : View
Products Affected
otrs
- otrs
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
