SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-53804

HIGH · CVSS 7.2 EPSS 1.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The OTRS Community Edition is vulnerable due to an authenticated OS command injection flaw in its PGP encryption module, allowing administrators to execute arbitrary operating system commands through crafted PGP binary paths and command options. This vulnerability poses a high risk as it enables attackers to execute commands with the privileges of the web server process, potentially compromising the entire system. Organizations using this software, particularly those with administrative access, should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-53804
Severity
HIGH
CVSS
7.2
EPSS
1.25%

Original NVD Description

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.