๐Ÿ” CVE Alert

CVE-2026-27823

UNKNOWN 0.0

Remote Code Execution Vulnerability in EGroupware

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication. The vulnerability stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability, which together enable full system compromise. This has been patched in versions 26.2.20260224 and 23.1.20260224.

CWE CWE-285
Vendor egroupware
Product egroupware
Published Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for egroupware egroupware

Be the first to know when new unknown vulnerabilities affecting egroupware egroupware are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

EGroupware / egroupware
<= 26.2.20260216 <= 23.1.20260131

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/EGroupware/egroupware/security/advisories/GHSA-h9qx-v5xp-ph8p