CVE 5.7 MEDIUM

Bypass DedicatedAgentToCustomerGroups Setting_CVE-2026-48189

5.7 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Description

An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected.

This issue affects OTRS:

* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X

Basic Information

ID CVE-2026-48189
Source OTRS
Published Jun 1, 2026 at 03:33

Affected Product

Vendor OTRS AG
Product OTRS
Version 7.0.x
Affected Versions OTRS AG OTRS 7.0.x
OTRS AG OTRS 8.0.x
OTRS AG OTRS 2023.x
OTRS AG OTRS 2024.x
OTRS AG OTRS 2025.x
OTRS AG OTRS 2026.x

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.