CVE-2026-48191: Wrong Permission Handling in Document Search Article Meta Filters
An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about number of affected CIs, SLA and services without gaining access to them.
This issue affects OTRS with STORM modules:
7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRSto a version that resolves this vulnerability.Fixed in 2026.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48191?
The severity of CVE-2026-48191 is rated as low, with a score of 3.5.
How do I fix CVE-2026-48191?
To fix CVE-2026-48191, update to OTRS version 2026.4.1 or later.
What software is affected by CVE-2026-48191?
CVE-2026-48191 affects OTRS with STORM modules in versions 7.0.X and 8.0.X.
What type of vulnerability is CVE-2026-48191?
CVE-2026-48191 is categorized as a wrong permission handling vulnerability.
Can I continue using OTRS 7 with CVE-2026-48191?
No, OTRS 7 will not receive any patches for CVE-2026-48191, so upgrading is necessary.