CVE-2020-1778: Otrs
Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.
When OTRS uses multiple backends for user authentication (with LDAP), agents are able to login even if the account is set to invalid. This issue affects OTRS; 8.0.9 and prior versions.
Affected products
- Otrs Otrs: up to and including 8.0.9
Published 2020-11-23. Last modified 2026-06-17.