PatchSiren cyber security CVE debrief
CVE-2026-48190 OTRS AG CVE debrief
An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be enabled and CustomerGroupSupport has to be used to be affected. This issue affects OTRS 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, and 2026.X before 2026.4.X.
- Vendor
- OTRS AG
- Product
- OTRS
- CVSS
- LOW 3.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-01
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-06-01
- Advisory updated
- 2026-07-22
Who should care
Organizations running OTRS with CMDB and CustomerGroupSupport enabled, particularly those with external customer portals or multi-tenant environments where customer data segregation is critical.
Technical summary
CVE-2026-48190 is a LOW severity (CVSS 3.5) vulnerability in OTRS affecting versions 7.0.X through 2026.X before 2026.4.X. The flaw involves incorrect handling of permissions in the External Interface and ConfigItem List module, allowing authenticated customers to query Configuration Item (CI) information when CMDB is enabled and CustomerGroupSupport is in use. The vulnerability is classified under CWE-276 (Incorrect Default Permissions) and requires network access, low attack complexity, authenticated privileges, and user interaction. Successful exploitation results in low confidentiality impact with no integrity or availability impact.
Defensive priority
low
Recommended defensive actions
- Verify whether CMDB and CustomerGroupSupport are enabled in your OTRS environment; if both are active, apply the relevant patch or upgrade to OTRS 2026.4.X or later.
- Review customer group permissions to ensure least-privilege access to ConfigItem data, limiting unnecessary read access to CMDB information.
- Monitor access logs for unusual or unauthorized ConfigItem list queries from customer accounts, particularly bulk or automated requests.
- If immediate patching is not feasible, consider temporarily restricting customer access to the ConfigItem List module until the update can be applied.
Evidence notes
The vulnerability requires CMDB to be enabled and CustomerGroupSupport to be used for exploitation. The CVSS v3.1 score of 3.5 (LOW) reflects the need for authenticated customer access and user interaction. The weakness is classified as CWE-276 (Incorrect Default Permissions).
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48190 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48190
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48190 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48190
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://otrs.com/release-notes/otrs-security-advisory-2026-04/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.