CVE-2026-53804: OS Command Injection Vulnerability in OTRS Community Edition
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
CVE-2026-53804 is an authenticated OS command injection vulnerability in the PGP encryption module of Centuran Consulting's OTRS Community Edition. This flaw allows administrators to execute arbitrary operating system commands by supplying crafted values for the PGP binary path and command options, which are concatenated unsafely into shell commands. The vulnerability affects versions up to and including 6.0.41. Currently, there is no evidence of public exploitation or proof-of-concept code. A patch has been released, and it is recommended to implement strict access controls and monitor configuration changes. The CVSS score for this vulnerability is 7.2, indicating high severity. Organizations using affected versions should update promptly to mitigate risks associated with this vulnerability.
Key Points: • CVE-2026-53804 allows OS command injection via unsanitized PGP configuration. • The vulnerability affects OTRS Community Edition versions up to 6.0.41. • A patch is available; strict access controls are recommended to mitigate risks.