« Volver al listado

CVE-2026-48187

Estado: AnalizadaMedia (5.7)—

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS:

Please note that ((OTRS)) Community Edition 6.x, OTRS 7.x and products based on the ((OTRS)) Community Edition also very likely to be affected

Detalles técnicos trazas, registros y código del informe original
  *  8.0.X
  *  2023.X
  *  2024.X
  *  2025.X
  *  2026.X before 2026.4.X

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-48187",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-48187",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-01T13:16:53.155447Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@otrs.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "security@otrs.com",
      "affectedData": [
        {
          "vendor": "OTRS AG",
          "modules": [
            "Mail Backend"
          ],
          "product": "OTRS",
          "versions": [
            {
              "status": "unknown",
              "version": "7.0.x"
            },
            {
              "status": "affected",
              "version": "8.0.x"
            },
            {
              "status": "affected",
              "version": "2023.x"
            },
            {
              "status": "affected",
              "version": "2024.x"
            },
            {
              "status": "affected",
              "version": "2025.x"
            },
            {
              "status": "affected",
              "version": "2026.x",
              "versionType": "patch",
              "lessThanOrEqual": "2026.3.x"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "OTRS AG",
          "product": "((OTRS)) Community Edition",
          "versions": [
            {
              "status": "unknown",
              "version": "6.x"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-06-01T04:16:22.410",
  "references": [
    {
      "url": "https://otrs.com/release-notes/otrs-security-advisory-2026-06/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@otrs.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@otrs.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        },
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS:\n\n  *  8.0.X\n  *  2023.X\n  *  2024.X\n  *  2025.X\n  *  2026.X before 2026.4.X\n\nPlease note that ((OTRS)) Community Edition 6.x, OTRS 7.x and products based on the ((OTRS)) Community Edition also very likely to be affected"
    },
    {
      "lang": "es",
      "value": "Una asignación incontrolada de recursos sin límites ni limitación en el manejo de correo electrónico en OTRS permite una asignación excesiva que puede llevar al aborto del servidor web. Este problema afecta a OTRS:\n\n  *  8.0.X\n  *  2023.X\n  *  2024.X\n  *  2025.X\n  *  2026.X antes de 2026.4.X\n\nTenga en cuenta que ((OTRS)) Community Edition 6.x, OTRS 7.x y los productos basados en la ((OTRS)) Community Edition también es muy probable que se vean afectados."
    }
  ],
  "lastModified": "2026-07-22T07:10:00.107",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5421FAF4-D702-4429-A186-6374A4306293",
              "versionEndIncluding": "6.0.32"
            },
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "650E99BF-9E05-496F-BD59-5542A95FD221",
              "versionEndIncluding": "8.0.37",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "476B2F02-24EA-43BB-BEA8-282D7D71B386",
              "versionEndExcluding": "2026.4.1",
              "versionStartIncluding": "2023.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@otrs.com"
}