CVE-2026-48187
Estado: AnalizadaMedia (5.7)—
An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS:
Please note that ((OTRS)) Community Edition 6.x, OTRS 7.x and products based on the ((OTRS)) Community Edition also very likely to be affected
Detalles técnicos trazas, registros y código del informe original
* 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
- Puntuación base: 5.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.36%
- Percentil entre todas las CVEs puntuadas: 27
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-400, CWE-770
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-48187",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-48187",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-01T13:16:53.155447Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@otrs.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "security@otrs.com",
"affectedData": [
{
"vendor": "OTRS AG",
"modules": [
"Mail Backend"
],
"product": "OTRS",
"versions": [
{
"status": "unknown",
"version": "7.0.x"
},
{
"status": "affected",
"version": "8.0.x"
},
{
"status": "affected",
"version": "2023.x"
},
{
"status": "affected",
"version": "2024.x"
},
{
"status": "affected",
"version": "2025.x"
},
{
"status": "affected",
"version": "2026.x",
"versionType": "patch",
"lessThanOrEqual": "2026.3.x"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "OTRS AG",
"product": "((OTRS)) Community Edition",
"versions": [
{
"status": "unknown",
"version": "6.x"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2026-06-01T04:16:22.410",
"references": [
{
"url": "https://otrs.com/release-notes/otrs-security-advisory-2026-06/",
"tags": [
"Vendor Advisory"
],
"source": "security@otrs.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@otrs.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
},
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS:\n\n * 8.0.X\n * 2023.X\n * 2024.X\n * 2025.X\n * 2026.X before 2026.4.X\n\nPlease note that ((OTRS)) Community Edition 6.x, OTRS 7.x and products based on the ((OTRS)) Community Edition also very likely to be affected"
},
{
"lang": "es",
"value": "Una asignación incontrolada de recursos sin límites ni limitación en el manejo de correo electrónico en OTRS permite una asignación excesiva que puede llevar al aborto del servidor web. Este problema afecta a OTRS:\n\n * 8.0.X\n * 2023.X\n * 2024.X\n * 2025.X\n * 2026.X antes de 2026.4.X\n\nTenga en cuenta que ((OTRS)) Community Edition 6.x, OTRS 7.x y los productos basados en la ((OTRS)) Community Edition también es muy probable que se vean afectados."
}
],
"lastModified": "2026-07-22T07:10:00.107",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5421FAF4-D702-4429-A186-6374A4306293",
"versionEndIncluding": "6.0.32"
},
{
"criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "650E99BF-9E05-496F-BD59-5542A95FD221",
"versionEndIncluding": "8.0.37",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "476B2F02-24EA-43BB-BEA8-282D7D71B386",
"versionEndExcluding": "2026.4.1",
"versionStartIncluding": "2023.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@otrs.com"
}