Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53804— OTRS Community Edition OS Command Injection via PGP Configuration

Quick assessment

Affected
Centuran Consulting OTRS Community Edition
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OTRS 社区版在其 PGP 加密模块中存在一个经过身份验证的操作系统命令注入漏洞。攻击者通过提供构造的 PGP 二进制文件路径和命令参数,能够以管理员身份执行任意操作系统命令。管理员输入的配置文件值未经过任何清理或过滤,就被直接拼接进 shell 命令中,从而导致任意命令执行。在恶意配置部署之后,即使是在正常的工单处理过程中,攻击者也可以以 Web 服务器进程的用户身份执行任意命令。

CVSS 7.2 · High EPSS 1.25% · P67

Affected Version Matrix 1

VendorProduct Version RangeStatus
Centuran Consulting OTRS Community Edition ≤ 6.0.41 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53804

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OTRS Community Edition OS Command Injection via PGP Configuration
Source: CVE Program / CVE List V5
Vulnerability Description
OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Centuran Consulting OTRS Community Edition 0 ~ 6.0.41 -

II. Public POCs for CVE-2026-53804

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53804

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53804 (1)

Security Blog Posts for CVE-2026-53804 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53804

No comments yet


Leave a comment