« Volver al listado

CVE-2026-48189

Estado: AnalizadaMedia (5.7)—

An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected.

This issue affects OTRS:

Detalles técnicos trazas, registros y código del informe original
  *  7.0.X
  *  8.0.X
  *  2023.X
  *  2024.X
  *  2025.X
  *  2026.X before 2026.4.X

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-48189",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-48189",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-01T13:14:38.008285Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@otrs.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "security@otrs.com",
      "affectedData": [
        {
          "vendor": "OTRS AG",
          "modules": [
            "Customer Backend"
          ],
          "product": "OTRS",
          "versions": [
            {
              "status": "affected",
              "version": "7.0.x"
            },
            {
              "status": "affected",
              "version": "8.0.x"
            },
            {
              "status": "affected",
              "version": "2023.x"
            },
            {
              "status": "affected",
              "version": "2024.x"
            },
            {
              "status": "affected",
              "version": "2025.x"
            },
            {
              "status": "affected",
              "version": "2026.x",
              "versionType": "patch",
              "lessThanOrEqual": "2026.3.x"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-06-01T04:16:22.723",
  "references": [
    {
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2026-03/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@otrs.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@otrs.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected.\n\nThis issue affects OTRS: \n\n  *  7.0.X\n  *  8.0.X\n  *  2023.X\n  *  2024.X\n  *  2025.X\n  *  2026.X before 2026.4.X"
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de validación de entrada incorrecta en el módulo de backend de clientes de OTRS permite acceder a información de clientes que está restringida a otros grupos. Tenga en cuenta que la característica debe estar habilitada y CustomerGroupSupport debe estar en uso para que se vea afectado.\n\nEste problema afecta a OTRS:\n\n  *  7.0.X\n  *  8.0.X\n  *  2023.X\n  *  2024.X\n  *  2025.X\n  *  2026.X anterior a 2026.4.X"
    }
  ],
  "lastModified": "2026-07-22T07:10:00.107",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "650E99BF-9E05-496F-BD59-5542A95FD221",
              "versionEndIncluding": "8.0.37",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "476B2F02-24EA-43BB-BEA8-282D7D71B386",
              "versionEndExcluding": "2026.4.1",
              "versionStartIncluding": "2023.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@otrs.com"
}