Home

Description

A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.3.X

PUBLISHED Reserved 2026-04-10 | Published 2026-04-20 | Updated 2026-04-20 | Assigner OTRS




MEDIUM: 4.5CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H

Problem types

CWE-400 Uncontrolled Resource Consumption

CWE-770 Allocation of Resources Without Limits or Throttling

Product status

Default status
unknown

7.0.x
affected

8.0.x
affected

2023.x
affected

2024.x
affected

2025.x
affected

2026.x (patch)
affected

Credits

Special thanks to Matthias Terlinde for reporting this vulnerability reporter

References

otrs.com/release-notes/otrs-security-advisory-2026-01/

cve.org (CVE-2026-6060)

nvd.nist.gov (CVE-2026-6060)

Download JSON