{"id":"CVE-2026-53804","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-53804","summary":"OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands…","details":"OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.","published":"2026-08-20T21:17:06.813","modified":"2026-08-20T21:17:06.813","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://h00die-gr3y.github.io/research/cve-2026-53804/"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/otrs-community-edition-os-command-injection-via-pgp-configuration"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T21:17:06.813"}}