CVE-2026-6060: Otrs AG Otrs
Medium severity, CVSS 4.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a DoS against the webserver. will be killed by the systemThis issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.3.X
Affected products
- Otrs AG Otrs: from 7.0, before 7.1 (fixed in 7.1); from 8.0, before 8.1 (fixed in 8.1); from 2023, before 2024 (fixed in 2024); from 2024, before 2025 (fixed in 2025); from 2025, before 2026 (fixed in 2026); from 2026, before 2026.3 (fixed in 2026.3)
Published 2026-04-20. Last modified 2026-06-17.