5.7
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Description
An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected.
This issue affects OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X
This issue affects OTRS:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X
Basic Information
ID
CVE-2026-48189
Source
OTRS
Published
Jun 1, 2026 at 03:33
Affected Product
Vendor
OTRS AG
Product
OTRS
Version
7.0.x
Affected Versions
OTRS AG OTRS 7.0.x
OTRS AG OTRS 8.0.x
OTRS AG OTRS 2023.x
OTRS AG OTRS 2024.x
OTRS AG OTRS 2025.x
OTRS AG OTRS 2026.x
OTRS AG OTRS 8.0.x
OTRS AG OTRS 2023.x
OTRS AG OTRS 2024.x
OTRS AG OTRS 2025.x
OTRS AG OTRS 2026.x