OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Centuran Consulting
Centuran Consulting otrs Community Edition |
|
| Vendors & Products |
Centuran Consulting
Centuran Consulting otrs Community Edition |
Thu, 20 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed. | |
| Title | OTRS Community Edition OS Command Injection via PGP Configuration | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-20T21:13:24.493Z
Updated: 2026-08-21T17:29:18.783Z
Reserved: 2026-06-10T20:14:32.829Z
Link: CVE-2026-53804
Updated: 2026-08-21T17:29:14.801Z
Status : Received
Published: 2026-08-20T21:17:06.813
Modified: 2026-08-21T18:16:48.550
Link: CVE-2026-53804
No data.