AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-48209

HIGH · CVSS 7.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-01 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.1. It affects Java. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-48209
Severity
HIGH
CVSS
7.1
EPSS
0.22%
Java

Original NVD Description

An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associated with ticket actions. By injecting malicious JavaScript into manipulated request URLs, attackers can execute arbitrary script code in the context of an authenticated agent session when the crafted link is opened. This issue affects OTRS: * 7.0.x Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected

Related CVEs

Other vulnerabilities affecting the same vendor(s)