Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-53804
Centuran Consulting OTRS Community Edition — OTRS Community Edition OS Command Injection via PGP Configuration
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N H N H H H 8.6 .0153 73.9 —
AFFECTED
Product Versions Fixed
OTRS Community Edition unspecified —
TIMELINE
Jun 10 Reserved by VulnCheck
Aug 20 Published (CNA: VulnCheck)
Aug 21 EXPLOIT PUBLISHED — CVE-2026-53804 (Centuran Consulting OTRS Community Edition). Public exploit reference added.
Description
OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are concatenated without sanitization into a shell command, enabling arbitrary command execution as the web server process user during normal ticket operations after the malicious configuration is deployed.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| June 10, 2026 | Reserved | Reserved by VulnCheck |
| August 20, 2026 | Published | Published (CNA: VulnCheck) |
| August 21, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-53804 (Centuran Consulting OTRS Community Edition). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Centuran Consulting | OTRS Community Edition | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-53804 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.