SECURITY ADVISORY
- PUBLISHING DATE:
- RELEASE TYPE:
- CRITICALITY:
- AFFECTED VERSION:
- July 27, 2026
- Security Patch Release
- LOW
- OTOBO 11.1 Beta
Security Fixes
- [Security] SessionID binding for web upload cache – Previously, the cache was being protected only by a cryptographically insecure random number, allowing authenticated attackers to guess it and access other users’ attachments during article creation. This vulnerability has been fixed. [#5835]
- [Security] Avoid recursion in the template generator / CVE-2025-26843 – Fixed a Denial of Service (DoS) vulnerability in ticket notifications and auto responses that allowed attackers to trigger infinite loops. [#5797]
- [Security] FormdraftID – A vulnerability has been fixed that previously allowed authenticated agents to delete drafts belonging to other users. [#5675]
- [Security] XSS vulnerabilities – Two XSS vulnerabilities have been fixed, one in AgentTicketEmailResend and one in the admin communication log. [#5791][#5790]
- [Security] POST forms – POST forms have been added for article and ticket actions, closing CSRF vulnerabilities on the MarkAsImportant and QuickClose actions. [#5817]
- [Security] SysConfig deployment – A permission check has been added to SysConfig deployment, closing a gap in the deployment process. [#5818]
Changes
Bugfixes
- [Bugfix] Ticket Info widget – Fixed an issue with how the Ticket Info widget in CustomerTicketZoom was displayed. [#5000]
- [Bugfix] Text Indent – Indent buttons in CKEditor are working again. [#5438]
- [Bugfix] OIDC Login Redirect – No more double URL-encoding. [#5787]
- [Bugfix] TicketAppointments-Event – The event is no longer triggered multiple times by mistake. [#4220]
Enhancements
- [Enhancement] Transition Action DynamicFieldSet allows a value to be interpreted as an “external source” key, by providing “ExternalSource” as additional parameter in the transition action. [#5882]
- [Enhancement] Transition Action TicketCustomerSet is now also compatible with reference fields provided via _Data tag. [#5902]
Next steps
Update to OTOBO 11.1.0 Beta2
We recommend that you fix the vulnerabilities and benefit from the latest improvements. Please update your system.
Security patch? System update?
No need to handle it alone.
As a support customer, just reach out via our portal or give us a quick call – we’re here to help.
Haven’t worked with us yet? Maybe now’s the perfect time. We’ll be happy to support your next update. Just get in touch – we’d love to hear from you!
Company
OTOBO | Simplify work and create exceptional service experiences.
The Source Code Owner and Maintainer of OTOBO.
Software
Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation
Report a security issues:
security@otobo.org

