Home

Description

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associated with ticket actions. By injecting malicious JavaScript into manipulated request URLs, attackers can execute arbitrary script code in the context of an authenticated agent session when the crafted link is opened. This issue affects OTRS: * 7.0.x Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected

PUBLISHED Reserved 2026-05-21 | Published 2026-06-01 | Updated 2026-06-01 | Assigner OTRS




HIGH: 7.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-116 Improper Encoding or Escaping of Output

Product status

Default status
unaffected

7.0.x
affected

Default status
affected

6.x
affected

Credits

Special thanks to William Bastos (@chor4o) for reporting this vulnerability finder

References

otrs.com/release-notes/otrs-security-advisory-2026-08/

cve.org (CVE-2026-48209)

nvd.nist.gov (CVE-2026-48209)

Download JSON