{"api_version":"1","generated_at":"2026-06-01T08:44:17+00:00","cve":"CVE-2026-48208","urls":{"html":"https://cve.report/CVE-2026-48208","api":"https://cve.report/api/cve/CVE-2026-48208.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-48208","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-48208"},"summary":{"title":"Denial-of-Service via SVG Rendering in Ticket","description":"An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).\n\nThis issue affects OTRS:\n\n  *  7.0.X\n  *  8.0.X\n  *  2023.X\n  *  2024.X\n  *  2025.X\n  *  2026.X before 2026.4.X\n\nPlease note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected","state":"PUBLISHED","assigner":"OTRS","published_at":"2026-06-01 04:16:23","updated_at":"2026-06-01 04:16:23"},"problem_types":["CWE-400","CWE-791","CWE-400 CWE-400 Uncontrolled Resource Consumption","CWE-791 CWE-791 Incomplete Filtering of Special Elements"],"metrics":[{"version":"3.1","source":"security@otrs.com","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://otrs.com/release-notes/otrs-security-advisory-2026-07/","name":"https://otrs.com/release-notes/otrs-security-advisory-2026-07/","refsource":"security@otrs.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-48208","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48208","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"OTRS AG","product":"OTRS","version":"affected 7.0.x","platforms":[]},{"source":"CNA","vendor":"OTRS AG","product":"OTRS","version":"affected 8.0.x","platforms":[]},{"source":"CNA","vendor":"OTRS AG","product":"OTRS","version":"affected 2023.x","platforms":[]},{"source":"CNA","vendor":"OTRS AG","product":"OTRS","version":"affected 2024.x","platforms":[]},{"source":"CNA","vendor":"OTRS AG","product":"OTRS","version":"affected 2025.x","platforms":[]},{"source":"CNA","vendor":"OTRS AG","product":"OTRS","version":"affected 2026.x 2026.3.x patch","platforms":[]},{"source":"CNA","vendor":"OTRS AG","product":"((OTRS)) Community Edition","version":"affected 6.x","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Update to OTRS 2026.4.1. or later. Please note that there will be no OTRS 7 patches","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Special thanks to Daniel Triznafor reporting this vulnerability","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"affected","modules":["Agent Frontend","External Interface"],"product":"OTRS","vendor":"OTRS AG","versions":[{"status":"affected","version":"7.0.x"},{"status":"affected","version":"8.0.x"},{"status":"affected","version":"2023.x"},{"status":"affected","version":"2024.x"},{"status":"affected","version":"2025.x"},{"lessThanOrEqual":"2026.3.x","status":"affected","version":"2026.x","versionType":"patch"}]},{"defaultStatus":"affected","modules":["Agent Frontend","External Interface"],"product":"((OTRS)) Community Edition","vendor":"OTRS AG","versions":[{"status":"affected","version":"6.x"}]}],"credits":[{"lang":"en","type":"reporter","value":"Special thanks to Daniel Triznafor reporting this vulnerability"}],"datePublic":"2026-06-01T07:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).</p><p></p><p>This issue affects OTRS:</p><ul><li>7.0.X</li><li>8.0.X</li><li>2023.X</li><li>2024.X</li><li>2025.X</li><li>2026.X before 2026.4.X</li></ul>Please note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected<p></p>"}],"value":"An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).\n\nThis issue affects OTRS:\n\n  *  7.0.X\n  *  8.0.X\n  *  2023.X\n  *  2024.X\n  *  2025.X\n  *  2026.X before 2026.4.X\n\nPlease note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected"}],"impacts":[{"capecId":"CAPEC-130","descriptions":[{"lang":"en","value":"CAPEC-130 Excessive Allocation"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-400","description":"CWE-400 Uncontrolled Resource Consumption","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-791","description":"CWE-791 Incomplete Filtering of Special Elements","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-01T03:32:38.926Z","orgId":"2e1bf29f-dc29-4ed8-830c-7b9348b6f0e8","shortName":"OTRS"},"references":[{"url":"https://otrs.com/release-notes/otrs-security-advisory-2026-07/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update to OTRS 2026.4.1. or later. Please note that there will be no OTRS 7 patches<br>"}],"value":"Update to OTRS 2026.4.1. or later. Please note that there will be no OTRS 7 patches"}],"source":{"advisory":"OSA-2026-07","defect":["Ticket#2026052110000251","Issue#4802"],"discovery":"EXTERNAL"},"title":"Denial-of-Service via SVG Rendering in Ticket","x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"2e1bf29f-dc29-4ed8-830c-7b9348b6f0e8","assignerShortName":"OTRS","cveId":"CVE-2026-48208","datePublished":"2026-06-01T03:32:38.926Z","dateReserved":"2026-05-21T12:12:49.645Z","dateUpdated":"2026-06-01T03:32:38.926Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-01 04:16:23","lastModifiedDate":"2026-06-01 04:16:23","problem_types":["CWE-400","CWE-791","CWE-400 CWE-400 Uncontrolled Resource Consumption","CWE-791 CWE-791 Incomplete Filtering of Special Elements"],"metrics":{"cvssMetricV31":[{"source":"security@otrs.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"48208","Ordinal":"1","Title":"Denial-of-Service via SVG Rendering in Ticket","CVE":"CVE-2026-48208","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"48208","Ordinal":"1","NoteData":"An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to browser-side resource exhaustion and denial of service when affected tickets are opened by an agent or customer. The issue can be exploited without JavaScript execution and is not mitigated by the configured Content Security Policy (CSP).\n\nThis issue affects OTRS:\n\n  *  7.0.X\n  *  8.0.X\n  *  2023.X\n  *  2024.X\n  *  2025.X\n  *  2026.X before 2026.4.X\n\nPlease note that ((OTRS)) Community Edition 6.x and before are vulnerable. Products based on the ((OTRS)) Community Edition also very likely to be affected","Type":"Description","Title":"Denial-of-Service via SVG Rendering in Ticket"}]}}}