An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend
This issue affects OTRS 2026.3.1
References
| Link | Resource |
|---|---|
| https://otrs.com/release-notes/otrs-security-advisory-2026-09/ | Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-05-31 22:16
Updated : 2026-07-22 07:10
NVD link : CVE-2026-48210
Mitre link : CVE-2026-48210
CVE.ORG link : CVE-2026-48210
JSON object : View
Products Affected
otrs
- otrs
