Impact
An authenticated administrator in OTRS Community Edition can supply crafted values for the PGP binary path and command options. These values are concatenated directly into a shell command during ticket operations, without sanitization. This allows the attacker to execute arbitrary operating‑system commands as the web server process user, enabling full control over the affected system with any privileges granted to that process.
Affected Systems
The flaw affects Centuran Consulting: OTRS Community Edition. No specific affected versions are disclosed, so all published releases are potentially vulnerable unless explicitly noted by the vendor.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. The EPSS score of 1% suggests a low but non-zero probability of exploitation, and the flaw is not listed in CISA’s KEV catalog, meaning no public exploitation has been reported. However, the flaw requires administrative access; an attacker who gains such credentials can exploit it during normal ticket processing with minimal effort, giving the web server process elevated-privilege command execution. Consequently, the risk is significant for environments where the web server runs with privileged rights.
OpenCVE Enrichment