CVE-2026-48209: Reflected XSS in authenticated agent context
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associated with ticket actions. By injecting malicious JavaScript into manipulated request URLs, attackers can execute arbitrary script code in the context of an authenticated agent session when the crafted link is opened.
This issue affects OTRS:
7.0.x
Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRS (OTRS Community Edition)to a version that resolves this vulnerability.Fixed in 2026.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48209?
The severity of CVE-2026-48209 is rated as high with a score of 7.1.
How do I fix CVE-2026-48209?
To fix CVE-2026-48209, you should update to the latest version of OTRS (2026.4.1 or later).
What types of attacks are possible with CVE-2026-48209?
CVE-2026-48209 allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks.
Which software is affected by CVE-2026-48209?
OTRS and OTRS Community Edition are affected by CVE-2026-48209.
What is the impact of CVE-2026-48209 on user data?
CVE-2026-48209 can lead to unauthorized access and manipulation of user data due to XSS vulnerabilities.