CVE Feed

    Dashboard / CVE / CVE-2026-53804

    CVE-2026-53804

    OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.

    Published:Aug 20, 2026
    Last Modified:Aug 21, 2026
    EPS:Aug 20, 2026
    EPSS Score:0.01222
    CVSS Score:7.2

    Affected Products

    Vendor
    Centuran Consulting
    Product
    Otrs Community Edition

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High