๐Ÿ” CVE Alert

CVE-2026-40187

UNKNOWN 0.0

Authenticated RCE via Malicious eTemplate Upload in EGroupware

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the VFS `/etemplates` mount. The `Widget::expand_name()` method passes template widget attribute values directly into a PHP `eval()` call with only double-quote escaping applied - **backtick characters are not escaped**. In PHP, backticks inside a double-quoted `eval()` string execute shell commands. This allows an admin-level user to escalate from web application access to arbitrary OS command execution on the server.

CWE CWE-78 CWE-95
Vendor egroupware
Product egroupware
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for egroupware egroupware

Be the first to know when new unknown vulnerabilities affecting egroupware egroupware are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

EGroupware / egroupware
<= 26.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/EGroupware/egroupware/security/advisories/GHSA-8737-2x9g-xjj7