PT-2026-79136 · Unknown · Otrs Community Edition

·

CVE-2026-53804

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OTRS Community Edition (affected versions not specified)
Description An authenticated OS command injection exists in the PGP encryption module. This issue occurs because configuration values provided by administrators are concatenated into a shell command without proper sanitization. An attacker with administrator privileges can execute arbitrary operating-system commands as the web server process user by supplying crafted values for the PGP binary path and command options during normal ticket operations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53804

Affected Products

Otrs Community Edition