CVE-2026-48210: Possible information disclosure via External Interface
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend
This issue affects OTRS 2026.3.1
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRSto a version that resolves this vulnerability.Fixed in 2026.4.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48210?
The severity of CVE-2026-48210 is classified as medium with a score of 5.7.
How do I fix CVE-2026-48210?
To fix CVE-2026-48210, update to the latest version of OTRS, specifically version 2026.4.1 or later.
What kind of vulnerability is CVE-2026-48210?
CVE-2026-48210 is categorized as an information disclosure vulnerability.
What causes CVE-2026-48210?
CVE-2026-48210 is caused by an improper default configuration in OTRS that enforces visibility settings for ticket articles.
What is the impact of CVE-2026-48210?
The impact of CVE-2026-48210 is the unintended exposure of internal ticket information to external users.