OTRS
cpe:2.3:a:otrs:otrs:*:*:*:*:*:*:*
- ~7.0
- ~8.0
- ~2023
- ~2024
- ~2025
- ~2026
A denial-of-service vulnerability has been identified in the SQL Box feature of the OTRS admin interface. This issue causes uncontrolled resource consumption, which can overwhelm the web server and disrupt service. The vulnerability affects OTRS versions 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, and 2026.X prior to 2026.3.X.
Exploitation of this vulnerability leads to excessive resource allocation, causing the web server to become unresponsive. The system may terminate the process handling the web server, further disrupting service.
Users can update to OTRS version 2026.3.1 or later. For OTRS 7 users, no patches will be available. As a workaround, SQL Box can be removed from the Admin Interface via System Configuration.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.