CVE-2026-48187 PUBLISHED

Email with special content can lead to DoS

Assigner: OTRS
Reserved: 21.05.2026 Published: 01.06.2026 Updated: 01.06.2026

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS:

  • 8.0.X
  • 2023.X
  • 2024.X
  • 2025.X
  • 2026.X before 2026.4.X

Please note that ((OTRS)) Community Edition 6.x, OTRS 7.x and products based on the ((OTRS)) Community Edition also very likely to be affected

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
CVSS Score: 5.7

Product Status

Vendor OTRS AG
Product OTRS
Versions Default: unknown
  • Version 7.0.x is unknown
  • Version 8.0.x is affected
  • Version 2023.x is affected
  • Version 2024.x is affected
  • Version 2025.x is affected
  • affected from 2026.x to 2026.3.x (incl.)
Vendor OTRS AG
Product ((OTRS)) Community Edition
Versions Default: unknown
  • Version 6.x is unknown

Solutions

Update to OTRS 2026.4.1. or later. Please note that there will be no OTRS 7 patches

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE
  • CWE-770 Allocation of Resources Without Limits or Throttling CWE

Impacts

  • CAPEC-130 Excessive Allocation