SECURITY ADVISORY
- PUBLISHING DATE:
- RELEASE TYPE:
- CRITICALITY:
- AFFECTED VERSION:
- July 27, 2026
- Security Patch Release
- LOW
- OTOBO 11.0
Security Fixes
- [Security] SessionID binding for web upload cache – Previously, the cache was being protected only by a cryptographically insecure random number, allowing authenticated attackers to guess it and access other users’ attachments during article creation. This vulnerability has been fixed. [#5835]
- [Security] Avoid recursion in the template generator / CVE-2025-26843 – Fixed a Denial of Service (DoS) vulnerability in ticket notifications and auto responses that allowed attackers to trigger infinite loops. [#5797]
- [Security] FormdraftID – A vulnerability has been fixed that previously allowed authenticated agents to delete drafts belonging to other users. [#5675]
- [Security] XSS vulnerabilities – Two XSS vulnerabilities have been fixed, one in AgentTicketEmailResend and one in the admin communication log. [#5791][#5790]
- [Security] AgentTicketBulk – Previously, the bulk action made it possible for agents to link tickets to another ticket they did not have access to. This missing permission check has been added. [#5723]
- [Security] SysConfig deployment – A permission check has been added to SysConfig deployment, closing a gap in the deployment process. [#5818]
Changes
- [Change] SystemConfiguration – Translation has been disabled for SystemConfiguration values within AdminSystemConfiguration. [#5641]
Bugfixes
- [Bugfix] DynamicField Database – Sorting of PossibleValues in the DynamicField Database details view has been fixed. [#5642]
- [Bugfix] Personal Preferences – Certain personal preferences of other agents failed to persist when edited by an admin. This issue has been fixed. [#5430]
- [Bugfix] Dynamic Field Ticket Categories – Color selection and translation are no longer failing for longer values due to truncation. [#5329]
- [Bugfix] Ticket Info widget – Fixed an issue with how the Ticket Info widget in CustomerTicketZoom was displayed. [#5000]
- [Bugfix] AgentTicketArticleEdit: – For edited articles, the original author was always shown as editor also. This has been fixed. [#5620]
- [Bugfix] DynamicField Import – Update Events are now set for Script Dynamic Fields upon import. [#5485]
- [Bugfix] DynamicField Text – New multivalue items start empty now instead of being pre-filled with the value of the previous item. [#5551]
- [Bugfix] DF Reference Agent – Works without filtering for groups now, too. [#5469]
- [Bugfix] Network Transport Endpoint – Is no longer limited to 250 characters. [#5262]
- [Bugfix] “Show deleted articles” button – Can be deactivated again. [#5445]
- [Bugfix] Text Indent – Indent buttons in CKEditor are working again. [#5438]
- [Bugfix] TicketAppointments-Event – The event is no longer triggered multiple times by mistake. [#4220]
Enhancements
- [Enhancement] Transition Action DynamicFieldSet allows a value to be interpreted as an “external source” key, by providing “ExternalSource” as additional parameter in the dynamic field settings. [#5882]
- [Enhancement] Transition Action TicketCustomerSet is now also compatible with reference fields provided via _Data tag. [#5902] .
Next steps
Update to OTOBO 11.0.17
We recommend that you fix the vulnerabilities and benefit from the latest improvements. Please update your system.
Security patch? System update?
No need to handle it alone.
As a support customer, just reach out via our portal or give us a quick call – we’re here to help.
Haven’t worked with us yet? Maybe now’s the perfect time. We’ll be happy to support your next update. Just get in touch – we’d love to hear from you!
Company
OTOBO | Simplify work and create exceptional service experiences.
The Source Code Owner and Maintainer of OTOBO.
Software
Service Management Platform
OTOBO Demo
OTOBO Download
OTOBO Documentation
Report a security issues:
security@otobo.org

