Executive brief
OTRS Community Edition is a popular open-source ticketing and customer service management system. The PGP encryption module, used to secure email communications within tickets, contains a vulnerability that allows authenticated administrators to execute arbitrary operating system commands on the server. An attacker with admin credentials can manipulate PGP configuration settings to inject malicious shell commands that execute with the privileges of the web server process, potentially leading to full system compromise, data theft, or lateral movement within the network.
Technical details
This is an authenticated OS command injection vulnerability (CWE-78) in the PGP encryption module, specifically in Kernel/System/Crypt/PGP.pm. The vulnerable code constructs shell commands by concatenating user-controlled configuration values (PGP::Bin and PGP::Options) directly into a command string without sanitization, then executes it via Perl backticks. An authenticated administrator can inject shell metacharacters through either the PGP binary path setting or command options to alter the executed command. The vulnerability is triggered when the PGP subsystem initializes (e.g., during ticket creation or status view operations). No patched versions have been released at publication time; mitigation requires restricting administrative access or disabling PGP functionality until vendor updates are available.
Affected products
- OTRS Community Edition all versions, including 6.0.41 and earlier
Timeline
- 2026-08-20: disclosed: Vulnerability published by h00die-gr3y
- 2026-08-18: other: Technical research published