OTRS是德国OTRS公司的一个服务管理解决方案。 OTRS 7.0.X版本、8.0.X版本、2023.X版本、2024.X版本、2025.X版本和2026.X版本至2026.4.X之前版本、Community Edition 6.0.x版本存在安全漏洞,该漏洞源于数据库层模块输入验证不当,可能导致未认证SQL注入并绕过身份验证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OTRS AG | ((OTRS)) Community Edition | 6.x |
affected |
| OTRS AG | OTRS | 7.0.x |
affected |
8.0.x |
affected | ||
2023.x |
affected | ||
2024.x |
affected | ||
2025.x |
affected | ||
2026.x≤ 2026.3.x |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OTRS AG | OTRS | 7.0.x | - |
|
| OTRS AG | ((OTRS)) Community Edition | 6.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48209 | 7.1 HIGH | Reflected XSS in authenticated agent context |
| CVE-2026-48208 | 6.5 MEDIUM | Denial-of-Service via SVG Rendering in Ticket |
| CVE-2026-48187 | 5.7 MEDIUM | Email with special content can lead to DoS |
| CVE-2026-48189 | 5.7 MEDIUM | Bypass DedicatedAgentToCustomerGroups Setting |
| CVE-2026-48191 | 3.5 LOW | Wrong Permission Handling in Document Search Article Meta Filters |
| CVE-2026-48190 | 3.5 LOW | Incorrect handling of permissions in External Interface Config Item List module |
No comments yet