-Infinity
0
Severity
8.6
OS Command Injection, Command Injection
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.

First published (updated )
Severity
5.7
AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS:

8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X

Please note that ((OTRS)) Community Edition 6.x, OTRS 7.x and products based on the ((OTRS)) Community Edition also very likely to be affected

First published (updated )
Severity
9.1
Input Validation, SQL Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NOBACKSLASHESCAPES SQL mode.

This issue affects OTRS:

7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X (OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

First published (updated )
Severity
5.7
Infoleak, Input Validation
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are restricted to other groups. Please note that the feature has to be anabled and CustomerGroupSupport has to be used to be affected.

This issue affects OTRS:

7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X

First published (updated )
Severity
3.5
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated customer to query the system for CI information. Please note that CMDB has to be anabled and CustomerGroupSupport has to be used to be affected.

This issue affects OTRS:

7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X

First published (updated )
Severity
3.5
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about number of affected CIs, SLA and services without gaining access to them.

This issue affects OTRS with STORM modules:

7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X

First published (updated )
Severity
6.5
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).

This issue affects OTRS:

7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.4.X

Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associated with ticket actions. By injecting malicious JavaScript into manipulated request URLs, attackers can execute arbitrary script code in the context of an authenticated agent session when the crafted link is opened.

This issue affects OTRS:

7.0.x

Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected

First published (updated )
Severity
5.7
Infoleak
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend

This issue affects OTRS 2026.3.1

First published (updated )
Severity
4.5
EPSS
0.03%
AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H

A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS:

7.0.X 8.0.X 2023.X 2024.X 2025.X 2026.X before 2026.3.X

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

A vulnerability in the External Interface of OTRS allows conclusions to be drawn about the existence of user accounts through different HTTP response codes and messages. This enables an attacker to systematically identify valid email addresses.

This issue affects:

OTRS 7.0.X

OTRS 8.0.X OTRS 2023.X OTRS 2024.X OTRS 2025.X

Remedy

Update to OTRS 2025.6.1. or later. Please note that there will be no OTRS 7 patches
First published (updated )
Severity
3.8
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user.

This issue affects:

OTRS 7.0.X

OTRS 8.0.X OTRS 2023.X OTRS 2024.X OTRS 2025.X

((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Remedy

Update to OTRS 2025.5.2. or later. Please note that there will be no OTRS 7 patches and that impact for OTRS 7 and prior is higher.
First published (updated )
Severity
6.5
CSRF
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible malicious web site, would send the authentication cookie, performing an unwanted read operation.

This issue affects:

OTRS 7.0.X OTRS 8.0.X OTRS 2023.X OTRS 2024.X OTRS 2025.x

Remedy

Update to OTRS 2025.2.x. Please note that there will be no OTRS 7 patches
First published (updated )
Severity
6.8
EPSS
0.04%
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions.

This issue affects:

OTRS 7.0.X

OTRS 8.0.X OTRS 2023.X OTRS 2024.X

Remedy

Update to OTRS 2025.1.x. Please note that there will be no OTRS 7 patches
First published (updated )
Severity
6.3
EPSS
0.04%
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator.

This issue affects:

OTRS 7.0.X

OTRS 8.0.X OTRS 2023.X OTRS 2024.X

((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Remedy

Update to OTRS 2025.1.x. Please note that there will be no OTRS 7 patches. Optional: Use MTA based sending on the OTRS instance e.g. postfix
First published (updated )
Severity
3.5
AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions.

This issue affects:

OTRS 7.0.X

OTRS 8.0.X OTRS 2023.X OTRS 2024.X

((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Remedy

Update to OTRS 2025.1.x. Please note that there will be no OTRS 7 patches
First published (updated )
Severity
5.4
Input Validation
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-Options to nosniff. An attacker could exploit this vulnerability by uploading or inserting content that would be treated as a different MIME type than intended.

This issue affects:

OTRS 7.0.X

OTRS 8.0.X OTRS 2023.X OTRS 2024.X

((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Remedy

Update to OTRS 2025.1.x. Please note that there will be no OTRS 7 patches
First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and debugging for the authentication backend has been enabled.

This issue affects:

OTRS from 7.0.X through 7.0.50 OTRS 8.0.X OTRS 2023.X OTRS from 2024.X through 2024.5.X ((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Remedy

Update to OTRS 2024.6.x or OTRS 7.0.51
First published (updated )
Severity
4.9
XSS
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the Process Management targeting other admins. This issue affects:

OTRS from 7.0.X through 7.0.50 OTRS 8.0.X OTRS 2023.X OTRS from 2024.X through 2024.5.X ((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Remedy

Update to OTRS 2024.6.x or OTRS 7.0.51
First published (updated )
Severity
4.9
XSS
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting (XSS) within the System Configuration targeting other admins. This issue affects:

OTRS from 7.0.X through 7.0.50 OTRS 8.0.X OTRS 2023.X OTRS from 2024.X through 2024.5.X ((OTRS)) Community Edition: 6.0.x

Products based on the ((OTRS)) Community Edition also very likely to be affected

Remedy

Update to OTRS 2024.6.x or OTRS 7.0.51
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an agent with read-only permissions to gain full access to a ticket. This issue arises in very rare instances when an admin has previously enabled the setting 'RequiredLock' of 'AgentFrontend::Ticket::InlineEditing::Property###Watch' in the system configuration.This issue affects OTRS:

8.0.X 2023.X from 2024.X through 2024.4.x

Remedy

Update to OTRS 2024.5.2
First published (updated )
Severity
5.7
EPSS
0.05%
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the TicketSearchLegacyEngine has been disabled by the administrator. This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x

First published (updated )
Severity
6.3
Path Traversal
AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L

The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits authenticated agents or customer users to upload potentially harmful files to directories accessible by the web server, potentially leading to the execution of local code like Perl scripts. This issue affects OTRS: from 7.0.X through 7.0.49, 8.0.X, 2023.X, from 2024.X through 2024.3.2; ((OTRS)) Community Edition: from 6.0.1 through 6.0.34.

Remedy

Update to OTRS 2024.4.3 or OTRS 7.0.50 (extended support only)
First published (updated )
Severity
9.8
EPSS
0.09%
Input Validation
AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

First published (updated )
Severity
7.5
EPSS
0.09%
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

First published (updated )
Severity
6.5
EPSS
0.05%
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malicious user can add more files to the comment.

This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023.X through 2023.1.1.

First published (updated )
Severity
8.1
EPSS
0.09%
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.

Remedy

Update to OTRS Patch 2023.1.1
First published (updated )
Severity
5.3
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

The loading of external images is not blocked, even if configured, if the attacker uses protocol-relative URL in the payload. This can be used to retreive the IP of the user.This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

First published (updated )
Severity
5.5
EPSS
0.46%
XSS, Input Validation
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

An attacker who is logged into OTRS as an user with privileges to create and change customer user data may manipulate the CustomerID field to execute JavaScript code that runs immediatly after the data is saved.The issue onlyoccurs if the configuration for AdminCustomerUser::UseAutoComplete was changed before. This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

Remedy

Update to OTRS 7.0.47 or OTRS 8.0.37.
First published (updated )
Severity
9.1
EPSS
0.35%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSLgetverifyresult() function is not used the certificated is trusted always and it can not be ensured that the certificate satisfies all necessary security requirements.

This could allow an attacker to use an invalid certificate to claim to be a trusted host, use expired certificates, or conduct other attacks that could be detected if the certificate is properly validated.

This issue affects OTRS: from 7.0.X before 7.0.47, from 8.0.X before 8.0.37; ((OTRS)) Community Edition: from 6.0.X through 6.0.34.

Remedy

Update to OTRS 7.0.47 or 8.0.37
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203