CVE-2026-48190

LOW

Incorrect handling of permissions in External Interface Config Item List module

Title source: cna
STIX 2.1

Description

An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be anabled and CustomerGroupSupport has to be used to be affected. This issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X

Scores

CVSS v3 3.5
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (7)
otrs/otrs 7.0.0 - 8.0.37
OTRS AG/OTRS 2023.x
OTRS AG/OTRS 2024.x
OTRS AG/OTRS 2025.x
OTRS AG/OTRS 2026.x - 2026.3.x
OTRS AG/OTRS 7.0.x
OTRS AG/OTRS 8.0.x
Published Jun 01, 2026
Tracked Since Jun 01, 2026