Description
A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.3.X
Scores
CVSS v3
4.5
EPSS
0.0003
EPSS Percentile
9.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-400
CWE-770
Status
published
Products (6)
OTRS AG/OTRS
2023.x
OTRS AG/OTRS
2024.x
OTRS AG/OTRS
2025.x
OTRS AG/OTRS
2026.x - 2026.2.x
OTRS AG/OTRS
7.0.x
OTRS AG/OTRS
8.0.x
Published
Apr 20, 2026
Tracked Since
Apr 21, 2026