← Späť na vyhľadávanie CVE

CVE-2026-48190

OTRS

Popis

An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be anabled and CustomerGroupSupport has to be used to be affected. This issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X

CVSS 3.5EPSS 0.14300000000000002%Riziko 0.35
Zobraziť zdroj
Zverejnené
2026-06-01 04:16:22
Dotknuté verzie
<2026.4
Typ
Core software
Posledná úprava
2026-07-22 07:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N