OS Command Injection Vulnerability in OTRS Community Edition PGP Encryption Module
CVE-2026-53804

8.6HIGH

Key Information:

Vendor
CVE Published:
20 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-53804?

The OTRS Community Edition is affected by an OS command injection flaw within its PGP encryption module. This vulnerability allows administrators to execute arbitrary commands on the operating system by crafting specific values for the PGP binary path and command options. Because user-supplied configuration values are concatenated into a shell command without proper sanitization, this vulnerability poses a risk of unauthorized command execution as the web server process user during standard ticket operations. It highlights the critical need for secure coding practices and validation of configuration input to prevent exploitation.

Affected Version(s)

OTRS Community Edition 0 <= 6.0.41

OTRS Community Edition 0 <= 6.0.41

OTRS Community Edition 0 <= 6357cdb89fe1dcc83a84fba14bd0f22898eea99a

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

h00die-gr3y
.