CVE-2026-48189: Bypass DedicatedAgentToCustomerGroups Setting
An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected.
This issue affects OTRS:
7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRSto a version that resolves this vulnerability.Fixed in 2026.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48189?
CVE-2026-48189 has a medium severity rating of 5.7.
What does CVE-2026-48189 affect?
CVE-2026-48189 affects the OTRS Customer Backend module in versions 7.0.X, 8.0.X, and 2026.
How do I fix CVE-2026-48189?
To fix CVE-2026-48189, update to OTRS version 2026.4.1 or later.
What is the risk associated with CVE-2026-48189?
CVE-2026-48189 has a risk score of 33, indicating a significant potential for impact.
What type of vulnerability is CVE-2026-48189?
CVE-2026-48189 is classified as an improper Input Validation vulnerability leading to information leakage.