This issue affects OTRS 2026.3.1
Project Subscriptions
No data.
No advisories yet.
Solution
Update to latest version of OTRS (2026.4.1. or later).
Workaround
Go to Forms###AgentFrontend::TicketArticle::Action::Forward in System Configuration. You will find that by Is visible for customer is a line Disabled: 1. Change it to Disabled to 0 or remove it. Caution: Still the user has to check the checkbox on forwarding and uncheck it if needed
Sun, 31 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users from disabling it via the UI. This leads to unintended exposure of internal ticket information to the External Frontend This issue affects OTRS 2026.3.1 | |
| Title | Possible information disclosure via External Interface | |
| Weaknesses | CWE-200 CWE-269 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2026-05-31T21:11:25.337Z
Reserved: 2026-05-21T12:12:49.646Z
Link: CVE-2026-48210
No data.
Status : Received
Published: 2026-05-31T22:16:55.133
Modified: 2026-05-31T22:16:55.133
Link: CVE-2026-48210
No data.
OpenCVE Enrichment
Updated: 2026-05-31T22:30:14Z