CVE-2026-27823
Remote Code Execution Vulnerability in EGroupware
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication. The vulnerability stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability, which together enable full system compromise. This has been patched in versions 26.2.20260224 and 23.1.20260224.
| CWE | CWE-285 |
| Vendor | egroupware |
| Product | egroupware |
| Published | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for egroupware egroupware
Be the first to know when new unknown vulnerabilities affecting egroupware egroupware are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
EGroupware / egroupware
<= 26.2.20260216 <= 23.1.20260131