CVE-2026-48191
Analyzed
Analyzed - Analysis Complete
Information Disclosure in OTRS STORM Document Search
Publication date: 2026-06-01
Last updated on: 2026-06-15
Assigner: OTRS AG
Description
Description
An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Filters modules allows gaining knowledge about number of affected CIs, SLA and services without gaining access to them.
This issue affects OTRS with STORM modules:
* 7.0.X
* 8.0.X
* 2023.X
* 2024.X
* 2025.X
* 2026.X before 2026.4.X
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| otrs | otrs | From 7.0.0 (inc) to 8.0.37 (inc) |
| otrs | otrs | From 2023.0.0 (inc) to 2026.4.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |