CVE-2026-6060: Possible DoS via SQL Box
A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS:
7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.3.X
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OTRSto a version that resolves this vulnerability.Fixed in 2026.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6060?
CVE-2026-6060 has a high severity rating due to its potential to cause a denial of service (DoS) situation.
How do I fix CVE-2026-6060?
To fix CVE-2026-6060, update your OTRS installation to the latest version that is not affected by this vulnerability.
Which versions of OTRS are affected by CVE-2026-6060?
CVE-2026-6060 affects OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, and up to 2026.3.X.
What type of vulnerability is CVE-2026-6060?
CVE-2026-6060 is classified as a vulnerability that leads to uncontrolled resource consumption, resulting in a DoS against the webserver.
Is there a workaround for CVE-2026-6060?
Currently, the recommended action for CVE-2026-6060 is to upgrade to a patched version of OTRS, as there are no known temporary workarounds.