CVE-2026-48190: Incorrect handling of permissions in External Interface Config Item List module
An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be anabled and CustomerGroupSupport has to be used to be affected.
This issue affects OTRS:
7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRS External Interface / ConfigItem Listto a version that resolves this vulnerability.Fixed in 2026.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48190?
The severity of CVE-2026-48190 is rated low with a score of 3.5.
How do I fix CVE-2026-48190?
To fix CVE-2026-48190, update to OTRS version 2026.4.1 or later.
What software is affected by CVE-2026-48190?
CVE-2026-48190 affects OTRS versions 7.0.X and 8.
What is the nature of the vulnerability in CVE-2026-48190?
CVE-2026-48190 involves incorrect handling of permissions in the OTRS External Interface Config Item List module.
Who can exploit CVE-2026-48190?
CVE-2026-48190 can be exploited by authenticated customers who have the necessary group support enabled.