CVE-2026-53804: OS Command Injection Vulnerability in OTRS Community Edition

CVE-2026-53804: OS Command Injection Vulnerability in OTRS Community Edition

First seen 22 Aug 2026, 02:17 UTC Feedlyradar.offseq.comnvd.nist.govvulners.comvuldb.com 90% similarity 64.5

Article Content

Browse articles
ThreatCluster

CVE-2026-53804 is an authenticated OS command injection vulnerability in the PGP encryption module of Centuran Consulting's OTRS Community Edition. This flaw allows administrators to execute arbitrary operating system commands by supplying crafted values for the PGP binary path and command options, which are concatenated unsafely into shell commands. The vulnerability affects versions up to and including 6.0.41. Currently, there is no evidence of public exploitation or proof-of-concept code. A patch has been released, and it is recommended to implement strict access controls and monitor configuration changes. The CVSS score for this vulnerability is 7.2, indicating high severity. Organizations using affected versions should update promptly to mitigate risks associated with this vulnerability.

Key Points: • CVE-2026-53804 allows OS command injection via unsanitized PGP configuration. • The vulnerability affects OTRS Community Edition versions up to 6.0.41. • A patch is available; strict access controls are recommended to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-20
CVE-2026-53804 published
CVE-2026-53804 was added to the CVE List, detailing an OS command injection vulnerability in OTRS.
NVD
2026-08-21
Patch released for OTRS Community Edition
A patch addressing CVE-2026-53804 has been made available to users of OTRS Community Edition.
Feedly
2026-08-22
Security advisory published
The vulnerability was detailed in various security advisories, emphasizing the need for immediate action.
radar.offseq.com

Community

Browse all →

Tracked Entities in This Story