Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. egroupware/egroupware
  4. ›
  5. CVE-2026-22243

CVE-2026-22243: EGroupware has SQL Injection in Nextmatch Filter Processing

January 28, 2026

Critical Authenticated SQL Injection in Nextmatch Widget Filter Processing

A critical SQL Injection vulnerability exists in the core components of EGroupware, specifically in the Nextmatch filter processing. The flaw allows authenticated attackers to inject arbitrary SQL commands into the WHERE clause of database queries. This is achieved by exploiting a PHP type juggling issue where JSON decoding converts numeric strings into integers, bypassing the is_int() security check used by the application.

References

  • github.com/EGroupware/egroupware
  • github.com/EGroupware/egroupware/releases/tag/23.1.20260113
  • github.com/EGroupware/egroupware/releases/tag/26.0.20260113
  • github.com/EGroupware/egroupware/security/advisories/GHSA-rvxj-7f72-mhrx
  • github.com/advisories/GHSA-rvxj-7f72-mhrx
  • nvd.nist.gov/vuln/detail/CVE-2026-22243

Code Behaviors & Features

Detect and mitigate CVE-2026-22243 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 23.1.20260113, all versions starting from 26.0.20251208 before 26.0.20260113

Fixed versions

  • 23.1.20260113
  • 26.0.20260113

Solution

Upgrade to versions 23.1.20260113, 26.0.20260113 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Source file

packagist/egroupware/egroupware/CVE-2026-22243.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 18 Feb 2026 00:17:30 +0000.