SECURITY ADVISORY
- RELEASE DATE:
- RELEASE TYPE:
- CRITICALITY:
- AFFECTED VERSIONS:
- 16 September 2026
- Security Patch Release
- HIGH
- OTOBO 11.1 Beta
Security Fixes
- [Security Fix – high criticality] In very specific scenarios, it was possible to gain access to privileges or third-party sessions in OTOBO environments using the “HTTP Basic Auth” authentication backend. [#6128]
Details on which systems are affected and recommendations for action to be found here.
- [Security] Preventing the listing of queue names in ‘AgentTicketQueue’. [#6092]
- [Security] Update of moment.js JavaScript library from 2.29.3 touf 2.30.1. [#6061]
- [Security] VirtualFS Write: Fix for the previously inadequate `Content` check. [#5572]
Enhancements
- [Enhancement] New implementation of the detect attachment postmaster filter. [#3422]
- [Enhancement] Nested LDAP Sync: Use complete information from ‘memberurl’ attribute. [#4696]
- [Enhancement] AdminDynamicField: Implemented field type filtering. [#5584]
- [Enhancement] Process Management: Implementation of global vs. local scoping and namespaces for process elements. [#5589]
- [Enhancement] Enabled DynamicField Database to be used in Sets. [#5915]
- [Enhancement] DynamicField Database: Further restricted filterable dynamic fields for OTOBO 11.1. [#5924]
- [Enhancement] Removed entrypoint.sh dependency for native systemd file. [#5956]
- [Enhancement] Added “server_tokens=off” to Nginx config. [#6046]
- [Enhancement] Enabled FieldTypeSettings for custom script fields. [#6053]
Bugfixes
- [Bugfix] Correction to the calculation of the total time for an article when it is edited multiple times. [#3592]
- [Bugfix] Revision of the display of DynamicField Richtext in the Process Activity Dialog. [#3720]
- [Bugfix] Login button was not acessible via tab key. [#5351]
- [Bugfix] Correctly populating $Param{Queue} in AgentDynamicFieldDBSearch.pm and CustomerDynamicFieldDBSearch.pm. [#5552]
- [Bugfix] VirtualFS Write: Improved check for `Content`. [#5572]
- [Bugfix] Fixed a bug that prevented the submission of forms in which an article Dynamic Field marked as required was hidden via ACL. [#5722]
- [Bugfix] Skipping similiar ticket ES search if tickets don’t have any articles. [#5930]
- [Bugfix] DynamicField Database: Corrected removing the last existing entry in a MultiValue element when clicking the minus button. [#5932]
- [Bugfix] Improved ExternalSourceTransform. [#5942]
- [Bugfix] Corrected ticket split action running into incorrectly quoted address line phrases. [#5945]
- [Bugfix] Corrected parsing of data regarding installed packages. [#5947]
- [Bugfix] Corrected storing of Customer Certificates. [#5952]
- [Bugfix] Adjusted line spacing within lists in CKEditor. [#5966]
- [Bugfix] SysConfigMigrateDynamicFieldNamespaces now also works for empty legacy entries in DynamicField::Namespaces. [#5970]
- [Bugfix] Enabled the admin entry for AdminOAuthTokenStore by default, so that the new OIDC functional accounts can be found. [#5971]
- [Bugfix] AdminDynamicFieldLens: Corrected ConfigItem field type names in whitelist. [#6025]
- [Bugfix] ACLs work properly on Set-inner fields in a Lens to a Set now. [#6086]
- [Bugfix] First time the page loads: Allow ACL calculations based on the dynamic field lens. [#6094]
- [Bugfix] DF Labels for Dynamic Fields in dynamic fields inside a DynamicField-Set can be translated, now. [#6099]
- [Bugfix] Corrected the display of values for a Lens with a Set Field as an attribute (e.g., in the ticket history). [#6104]
- [Bugfix] Improvements on ConfigItem ACL import. [#6119]
- and more.
Next steps
Update to OTOBO 11.1.0 Beta3
We strongly recommend updating your systems as soon as possible.
Security Patch? System Update?
We’re happy to help. Just get in touch.
Company
OTOBO | Simplify work and create exceptional service experiences.
The Source Code Owner and Maintainer of OTOBO.
Software
Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation
Report a security issues:
security@otobo.org


