SECURITY ADVISORY
- RELEASE DATE:
- RELEASE TYPE:
- CRITICALITY:
- AFFECTED VERSIONS
- 16 September 2026
- Security Patch Release
- HIGH
- OTOBO 10.1
Security Fixes
- [Security Fix – high criticality] In very specific scenarios, it was possible to gain access to privileges or third-party sessions in OTOBO environments using the “HTTP Basic Auth” authentication backend. [#6128]
Details on which systems are affected and recommendations for action to be found here.
Enhancements
- [Enhancement] Nested LDAP Sync: Use complete information from ‘memberurl’ attribute. [#4696]
Bugfixes
- [Bugfix] Login button was not acessible via tab key. [#5351]
- [Bugfix] Correctly populating $Param{Queue} in AgentDynamicFieldDBSearch.pm and CustomerDynamicFieldDBSearch.pm. [#5552]
- [Bugfix] Fixed a bug that prevented the submission of forms in which an article Dynamic Field marked as required was hidden via ACL. [#5722]
Next Steps
Update to OTOBO 10.1.19
We strongly recommend updating the system as soon as possible.
Need support?
We’re happy to help. Just get in touch.
Company
OTOBO | Simplify work and create exceptional service experiences.
The Source Code Owner and Maintainer of OTOBO.
Software
Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation
Report a security issues:
security@otobo.org

