---
id: CVE-2026-53804
title: >-
  OTRS Community Edition contains an authenticated OS command injection
  vulnerability in the PGP encryption module that allows administrators to
  execute arbitrary operating-system commands by supplying crafted values for
  the PGP binary pat…
summary: >-
  OTRS Community Edition contains an authenticated OS command injection
  vulnerability in the PGP encryption module that allows administrators to
  execute arbitrary operating-system commands by supplying crafted values for
  the PGP binary pat…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-08-20'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:06:30.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53804'
references:
  - url: 'https://h00die-gr3y.github.io/research/cve-2026-53804/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/otrs-community-edition-os-command-injection-via-pgp-configuration
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.01533
epssPercentile: 0.73688
ingestedAt: '2026-09-24T20:51:40.213Z'
---

## Overview

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
