Description
A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication. The vulnerability stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability, which together enable full system compromise. This has been patched in versions 26.2.20260224 and 23.1.20260224.
Published: 2026-07-20
Score: 8.7 High
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in EGroupware arises from improper authorization checks combined with a file write primitive and an arbitrary file read flaw, allowing an attacker who is logged in to execute arbitrary commands on the server. If self‑registration is enabled, the flaw can be abused without any credential, giving the attacker full control. The attacker could thereby compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

Affected vendors: EGroupware. The security advisory states that the issue was fixed in release 26.2.20260224 and 23.1.20260224. All earlier releases remain vulnerable, especially those that allow self‑registration.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of 1.03% indicates a very low, but nonzero, likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, so the public exploitation risk may be limited but cannot be ruled out. Inferred from the description, the attack vector requires authentication for most cases, unless the application is set to allow self‑registration, in which case the flaw can be exploited by an unauthenticated user. No network restrictions are mentioned, indicating the attack can be performed from any reachable host that can access the web application.

Generated by OpenCVE AI on August 1, 2026 at 07:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for EGroupware 26.2.20260224 or 23.1.20260224 to eliminate the authorization and file manipulation flaws.
  • If disabling self‑registration is feasible, do so to prevent unauthenticated exploitation of the file read/write path.
  • Ensure that all file system permissions for EGroupware installation directories enforce least‑privilege and that only authorized services can write to these locations.

Generated by OpenCVE AI on August 1, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h9qx-v5xp-ph8p EGroupware has a Remote Code Execution Vulnerability
History

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Egroupware
Egroupware egroupware
Vendors & Products Egroupware
Egroupware egroupware

Mon, 20 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication. The vulnerability stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability, which together enable full system compromise. This has been patched in versions 26.2.20260224 and 23.1.20260224.
Title Remote Code Execution Vulnerability in EGroupware
Weaknesses CWE-285
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Egroupware Egroupware
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-21T15:47:35.591Z

Reserved: 2026-02-24T02:32:39.799Z

Link: CVE-2026-27823

cve-icon Vulnrichment

Updated: 2026-07-21T15:47:31.335Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:15:03Z

Weaknesses