CVE-2026-53804
Received Received - Intake

Authenticated OS Command Injection in OTRS Community Edition PGP Module

Vulnerability report for CVE-2026-53804, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: VulnCheck

Description

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
otrs community_edition *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OTRS Community Edition has an authenticated OS command injection flaw in its PGP encryption module. Administrators can exploit this by providing malicious values for the PGP binary path and command options. These values are directly concatenated into a shell command without sanitization, allowing arbitrary command execution as the web server user during normal ticket operations after deployment.

Detection Guidance

Check OTRS Community Edition configurations for PGP encryption module settings. Look for suspicious or unexpected values in the PGP binary path or command options fields. Review system logs for unusual commands executed by the web server process user during ticket operations.

Impact Analysis

If you are an administrator of OTRS Community Edition, an attacker with admin access could execute arbitrary commands on your system. This could lead to full system compromise, data theft, or disruption of services. Even if not an admin, if an attacker gains admin privileges, they could exploit this to escalate their access.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations may face fines, legal penalties, and reputational damage due to non-compliance if this flaw is exploited to access regulated data.

Mitigation Strategies

Immediately update OTRS Community Edition to the latest patched version. Disable or restrict access to the PGP encryption module if not required. Review and sanitize all administrator-supplied configuration values in the PGP module. Monitor system logs for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53804. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart