OS Command Injection Vulnerability in OTRS Community Edition PGP Encryption Module
CVE-2026-53804
Key Information:
- Vendor
Centuran Consulting
- Status
- Vendor
- CVE Published:
- 20 August 2026
Badges
What is CVE-2026-53804?
The OTRS Community Edition is affected by an OS command injection flaw within its PGP encryption module. This vulnerability allows administrators to execute arbitrary commands on the operating system by crafting specific values for the PGP binary path and command options. Because user-supplied configuration values are concatenated into a shell command without proper sanitization, this vulnerability poses a risk of unauthorized command execution as the web server process user during standard ticket operations. It highlights the critical need for secure coding practices and validation of configuration input to prevent exploitation.
Affected Version(s)
OTRS Community Edition 0 <= 6.0.41
OTRS Community Edition 0 <= 6.0.41
OTRS Community Edition 0 <= 6357cdb89fe1dcc83a84fba14bd0f22898eea99a
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
