SECURITY ADVISORY
- PUBLISHING DATE:
- RELEASE TYPE:
- CRITICALITY:
- AFFECTED VERSION:
- July 27, 2026
- Security Patch Release
- LOW
- OTOBO 10.1
Security Fixes
- [Security] SessionID binding for web upload cache – Previously, the cache was being protected only by a cryptographically insecure random number, allowing authenticated attackers to guess it and access other users’ attachments during article creation. This vulnerability has been fixed. [#5835]
- [Security] Avoid recursion in the template generator / CVE-2025-26843 – Fixed a Denial of Service (DoS) vulnerability in ticket notifications and auto responses that allowed attackers to trigger infinite loops. [#5797]
- [Security] FormdraftID – A vulnerability has been fixed that previously allowed authenticated agents to delete drafts belonging to other users. [#5675]
- [Security] XSS vulnerabilities – Two XSS vulnerabilities have been fixed, one in AgentTicketEmailResend and one in the admin communication log. [#5791][#5790]
- [Security] AgentTicketBulk – Previously, the bulk action made it possible to link tickets to another ticket the agent did not have access to. This missing permission check has been added. [#5723]
- [Security] SysConfig deployment – A permission check has been added to SysConfig deployment, closing a gap in the deployment process. [#5818]
Changes
- [Change] SystemConfiguration – Translation has been disabled for SystemConfiguration values within AdminSystemConfiguration. [#5641]
Bugfixes
- [Bugfix] DynamicField Database – Sorting of PossibleValues in the DynamicField Database details view has been fixed. [#5642]
- [Bugfix] Personal Preferences – Certain personal preferences of other agents failed to persist when edited by an admin. [#5430]
- [Bugfix] Dynamic Field Ticket Categories – Fixed an issue where color selection and translation failed for longer values due to truncation. [#5329]
Next steps
Update to OTOBO 10.1.18
We recommend that you fix the vulnerabilities and benefit from the latest improvements. Please update your system.
Security patch? System update?
No need to handle it alone.
As a support customer, just reach out via our portal or give us a quick call – we’re here to help.
Haven’t worked with us yet? Maybe now’s the perfect time. We’ll be happy to support your next update. Just get in touch – we’d love to hear from you!
Company
OTOBO | Simplify work and create exceptional service experiences.
The Source Code Owner and Maintainer of OTOBO.
Software
Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation
Report a security issues:
security@otobo.org


