Security readout for executives and security teams
Plain-English summary
Affected OTRS support bundles may accidentally include private S/MIME or PGP keys when the containing folder is not hidden. This turns a routine support artifact into sensitive key material. Business urgency depends on whether support bundles were generated, stored, or shared outside a tightly controlled administrative group.
Executive priority
Prioritize as moderate unless support bundles were shared externally or retained broadly. The main business risk is exposure of private mail encryption or signing keys, which can undermine confidentiality and trust in signed communications.
Technical view
CVE-2021-36096 is an information exposure issue in OTRS support bundle generation. The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N, reflecting high confidentiality impact but requiring high privileges and user interaction. Affected versions include ((OTRS)) Community Edition 6.0.1 and later, OTRS 7.0.x through 7.0.28, and 8.0.x through 8.0.15.
Likely exposure
Exposure is likely limited to organizations running affected OTRS versions that generated support bundles while S/MIME or PGP secret material was in a non-hidden folder. Risk increases if bundles were attached to tickets, emailed, uploaded to vendors, or retained in shared storage.
Exploitation context
The bundle states no KEV listing, and no cited source confirms active exploitation. Practical abuse would depend on obtaining a generated support bundle containing private key material. The issue is not described as unauthenticated remote compromise; the CVSS vector requires high privileges and user interaction.
Researcher notes
Evidence is limited to CVE metadata and the OTRS advisory reference. The provided sources do not name a specific fixed version, exploit campaign, or complete workaround. Avoid assuming internet-scale exploitability; focus validation on affected versions, bundle generation history, and handling of generated artifacts.
Mitigation direction
- Review the OTRS security advisory for vendor-supported update or configuration guidance.
- Restrict support bundle generation and access to trusted administrators only.
- Treat historical support bundles from affected systems as sensitive key material.
- If bundles were shared externally, follow incident response for exposed cryptographic secrets.
- Check vendor guidance before changing key storage behavior or product configuration.
Validation and detection
- Inventory OTRS Community Edition 6.0.1 and later deployments.
- Identify OTRS 7.0.x systems at or below 7.0.28.
- Identify OTRS 8.0.x systems at or below 8.0.15.
- Review whether support bundles were generated on affected systems.
- Check where generated support bundles were stored, attached, or shared.
- Assess whether S/MIME or PGP private material was present in non-hidden folders.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-200: Information exposure and cloud metadata lookup
Information exposure and SSRF weaknesses can make discovery, cloud metadata, and credential material review relevant. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCredential and access behavior lookup
The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-36096 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.2 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N0.94.2Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.2MediumVector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://otrs.com/release-notes/otrs-security-advisory-2021-10/CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
