Impact
The vulnerability in EGroupware arises from improper authorization checks combined with a file write primitive and an arbitrary file read flaw, allowing an attacker who is logged in to execute arbitrary commands on the server. If self‑registration is enabled, the flaw can be abused without any credential, giving the attacker full control. The attacker could thereby compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected vendors: EGroupware. The security advisory states that the issue was fixed in release 26.2.20260224 and 23.1.20260224. All earlier releases remain vulnerable, especially those that allow self‑registration.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of 1.03% indicates a very low, but nonzero, likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, so the public exploitation risk may be limited but cannot be ruled out. Inferred from the description, the attack vector requires authentication for most cases, unless the application is set to allow self‑registration, in which case the flaw can be exploited by an unauthenticated user. No network restrictions are mentioned, indicating the attack can be performed from any reachable host that can access the web application.
OpenCVE Enrichment
Github GHSA