boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-53804

Centuran Consulting OTRS Community Edition — OTRS Community Edition OS Command Injection via PGP Configuration
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   H   N   H   H   H    8.6   .0153   73.9     —
AFFECTED
  Product                 Versions     Fixed
  OTRS Community Edition  unspecified  —
TIMELINE
  Jun 10  Reserved by VulnCheck
  Aug 20  Published (CNA: VulnCheck)
  Aug 21  EXPLOIT PUBLISHED — CVE-2026-53804 (Centuran Consulting OTRS Community Edition). Public exploit reference added.
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred

Description

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 10, 2026ReservedReserved by VulnCheck
August 20, 2026PublishedPublished (CNA: VulnCheck)
August 21, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-53804 (Centuran Consulting OTRS Community Edition). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Centuran ConsultingOTRS Community Edition———

Weaknesses

CWE-78

References (2)

Related

Authoritative record: CVE-2026-53804 at cve.org

Vendors: centuran consulting

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-53804 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.