← Back

CVE-2026-48210

nvd nist
Published: May 31, 2026Modified: Jul 22, 2026

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: security@otrs.com (Secondary)

Description

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue affects OTRS 2026.3.1

Affected (1)

Products: Otrs: Otrs
1 product
Otrs
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2026.3.1

References (1)

Source: security@otrs.com
MitigationVendor Advisory

Timeline

No history available yet.