Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. egroupware/egroupware
  4. ›
  5. CVE-2026-27823

CVE-2026-27823: EGroupware has a Remote Code Execution Vulnerability

July 7, 2026

A critical vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication.

The vulnerability stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability, which together enable full system compromise.

References

  • github.com/EGroupware/egroupware/security/advisories/GHSA-h9qx-v5xp-ph8p
  • github.com/advisories/GHSA-h9qx-v5xp-ph8p
  • nvd.nist.gov/vuln/detail/CVE-2026-27823

Code Behaviors & Features

Detect and mitigate CVE-2026-27823 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 23.1.20260224, all versions starting from 26.0.20251208 before 26.2.20260224

Fixed versions

  • 23.1.20260224
  • 26.2.20260224

Solution

Upgrade to versions 23.1.20260224, 26.2.20260224 or above.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-639: Authorization Bypass Through User-Controlled Key
  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

packagist/egroupware/egroupware/CVE-2026-27823.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 11 Jul 2026 00:19:03 +0000.