Impact
The vulnerability stems from an incorrect permission check in OTRS's External Interface ConfigItem List module. An authenticated customer can exploit this flaw to query ConfigItem objects and retrieve internal CI data. The flaw does not affect system integrity or availability, but it exposes configuration information that could assist in further attacks.
Affected Systems
Affected systems are OTRS AG’s OTRS platform versions 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, and all 2026.X releases prior to 2026.4.1. The Configuration Management Database (CMDB) must be enabled, and CustomerGroupSupport features must be active for exploitation to be possible.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity. EPSS data is not available and the vulnerability is not listed in CISA KEV. Exploitation requires an authenticated customer in an environment where the CMDB is enabled and CustomerGroupSupport is used, limiting the attack surface. Consequently, the risk of exploitation is low but not zero in affected configurations.
OpenCVE Enrichment