OTRS是德国OTRS公司的一个服务管理解决方案。 OTRS 8.0.X版本、2023.X版本、2024.X版本、2025.X版本和2026.X版本至2026.4.X之前版本存在安全漏洞,该漏洞源于电子邮件处理中资源分配不受控制,可能导致Web服务器中止。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OTRS AG | ((OTRS)) Community Edition | 6.x |
unknown |
| OTRS AG | OTRS | 7.0.x |
unknown |
8.0.x |
affected | ||
2023.x |
affected | ||
2024.x |
affected | ||
2025.x |
affected | ||
2026.x≤ 2026.3.x |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | OTRS | 7.0.x | - |
|
| OTRS AG | ((OTRS)) Community Edition | 6.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48188 | 9.1 CRITICAL | SQL Injection via MySQL Quote Method |
| CVE-2026-48209 | 7.1 HIGH | Reflected XSS in authenticated agent context |
| CVE-2026-48208 | 6.5 MEDIUM | Denial-of-Service via SVG Rendering in Ticket |
| CVE-2026-48189 | 5.7 MEDIUM | Bypass DedicatedAgentToCustomerGroups Setting |
| CVE-2026-48191 | 3.5 LOW | Wrong Permission Handling in Document Search Article Meta Filters |
| CVE-2026-48190 | 3.5 LOW | Incorrect handling of permissions in External Interface Config Item List module |
No comments yet