Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 8 min 109 bronnen 1 kritiek 3 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2026-48190

LOW · 3.5 CVSS Gepubliceerd: CWE-276

Beschrijving

An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be anabled and CustomerGroupSupport has to be used to be affected.

This issue affects OTRS:

* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X

Vendors

Otrs

Affected products

Otrs

References