PT-2026-79136 · Unknown · Otrs Community Edition
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OTRS Community Edition (affected versions not specified)
Description
An authenticated OS command injection exists in the PGP encryption module. This issue occurs because configuration values provided by administrators are concatenated into a shell command without proper sanitization. An attacker with administrator privileges can execute arbitrary operating-system commands as the web server process user by supplying crafted values for the PGP binary path and command options during normal ticket operations.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Otrs Community Edition