CVE-2026-48187

MEDIUM

OTRS Email Handling - Resource Exhaustion Denial of Service

Title source: manual
STIX 2.1

Description

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS: * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X Please note that ((OTRS)) Community Edition 6.x, OTRS 7.x and products based on the ((OTRS)) Community Edition also very likely to be affected

Scores

CVSS v3 5.7
EPSS 0.0018
EPSS Percentile 7.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400 CWE-770
Status published
Products (9)
otrs/otrs < 6.0.32
otrs/otrs 7.0.0 - 8.0.37
OTRS AG/((OTRS)) Community Edition 6.x
OTRS AG/OTRS 2023.x
OTRS AG/OTRS 2024.x
OTRS AG/OTRS 2025.x
OTRS AG/OTRS 2026.x - 2026.3.x
OTRS AG/OTRS 7.0.x
OTRS AG/OTRS 8.0.x
Published Jun 01, 2026
Tracked Since Jun 01, 2026