An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the system if the MySQL/MariaDB server is configured with the NO_BACKSLASH_ESCAPES SQL mode. This issue affects OTRS: * 7.0.X * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X * (OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected
The vulnerability results from improper input validation in the database layer module. An attacker can submit a crafted query containing a malicious SQL payload without needing to possess any privileges. The attack is only possible when the MySQL or MariaDB server is configured with the SQL NO_BACKSLASH_ESCAPES mode — in this mode, the standard backslash escape mechanism is disabled, which prevents the application from effectively neutralizing malicious input strings. This allows manipulation of SQL queries and bypassing user identity verification.
An attacker without any privileges can gain unauthorized access to the OTRS system by bypassing the login mechanism, leading to high violation of confidentiality and integrity of processed data.
OTRS should be updated to version 2026.4.X or newer. For other branches (7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X) and OTRS Community Edition 6.0.x, patches available from the vendor should be applied according to the references (https://otrs.com/release-notes/otrs-security-advisory-2026-02/). As an immediate workaround, removing the NO_BACKSLASH_ESCAPES mode from the MySQL/MariaDB server configuration can be considered if operationally acceptable.
OTRS in versions 7.0.X, 8.0.X, 2023.X, 2024.X, 2025.X, and 2026.X before 2026.4.X; OTRS Community Edition in version 6.0.x; products based on OTRS Community Edition are likely also vulnerable. The vulnerability is revealed only when the MySQL/MariaDB server is configured with the SQL NO_BACKSLASH_ESCAPES mode.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NOtrs
APPOtrs≤ 6.0.327.0.0 – 8.0.372023.0.0 – 2026.4.1 (excl.)
Related vulnerabilities
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling al...
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which ...
The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL o...
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTas...
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as Agent authenticat...