Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module. Administrator-supplied configuration values for the PGP binary path and command options are concatenated without sanitization into shell commands, enabling arbitrary command execution as the web server process user during normal ticket operations after malicious configuration is deployed.
An authenticated administrator can execute arbitrary operating system commands as the web server process user by supplying crafted PGP binary path and command option values through the configuration interface.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Reference:
Update OTRS Community Edition to a patched version. Implement strict access controls to limit who can modify PGP encryption module configuration. Monitor administrator configuration changes for suspicious PGP binary paths or command options. Restrict the web server process user privileges to the minimum necessary for OTRS operations.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
NVD published the first details for CVE-2026-53804
A CVSS base score of 7.2 has been assigned.
Feedly found the first article mentioning CVE-2026-53804 . See article
GitHub Advisories released a security advisory .
An authenticated OS command injection vulnerability exists in the PGP encryption module of OTRS Community Edition, allowing administrators to execute arbitrary commands as the web server process user due to unsanitized configuration values. The CVSS score indicates a high criticality, but there is currently no evidence of exploitation in the wild or public proof-of-concept. A patch is available, and it is recommended to implement strict access controls and monitor configuration changes to mitigate the risk. See article
CVE-2026-53804 - Exploits & Severity - Feedly
CVE-2026-53804 - Exploits & Severity - Feedly
CVE-2026-53804: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Centuran Consulting OTRS Community Edition
CVE-2026-53804 OTRS Community Edition OS Command Injection via PGP Configuration
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
