CVE-2026-6060 PUBLISHED

Possible DoS via SQL Box

Assigner: OTRS
Reserved: 10.04.2026 Published: 20.04.2026 Updated: 20.04.2026

A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS: 

  • 7.0.X
  • 8.0.X
  • 2023.X
  • 2024.X
  • 2025.X
  • 2026.X before 2026.3.X

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
CVSS Score: 4.5

Product Status

Vendor OTRS AG
Product OTRS
Versions Default: unknown
  • Version 7.0.x is affected
  • Version 8.0.x is affected
  • Version 2023.x is affected
  • Version 2024.x is affected
  • Version 2025.x is affected
  • affected from 2026.x to 2026.2.x (incl.)

Workarounds

Remove SQL Box from Admin Interface via System Configuration

Solutions

Update to OTRS 2026.3.1. or later. Please note that there will be no OTRS 7 patches

Credits

  • Special thanks to Matthias Terlinde for reporting this vulnerability reporter

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE
  • CWE-770 Allocation of Resources Without Limits or Throttling CWE

Impacts

  • CAPEC-125 Flooding
  • CAPEC-130 Excessive Allocation