PT-2026-56210 · Egroupware+1 · Egroupware+1

CVE-2026-27823

·

Published

2026-07-07

·

Updated

2026-07-21

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions EGroupware versions prior to 26.2.20260224 EGroupware versions prior to 23.1.20260224
Description An issue allows an authenticated attacker to execute arbitrary commands on the server, which may lead to full system compromise. If user self-registration is enabled, the issue can be exploited without prior authentication. The flaw results from improper authorization checks combined with an arbitrary file read and a file write primitive. Specifically, the ajax upload() function in EGroupwareSmallParTWidgetsSmallPartMediaRecorder fails to properly validate the participant role variable, which is derived from user-controlled request data, allowing attackers to bypass teacher role checks. This enables an arbitrary file write via the video type variable, allowing path traversal to overwrite files such as header.inc.php. Additionally, the download function in importexport export ui is susceptible to arbitrary file read through the filename parameter. By combining these flaws, an attacker can read a valid system file, modify it with malicious PHP code, and overwrite it to achieve Remote Code Execution (RCE) upon server restart or OPcache expiration.
Recommendations Update EGroupware to version 26.2.20260224 or later. Update EGroupware to version 23.1.20260224 or later. As a temporary mitigation, disable user self-registration to prevent unauthenticated exploitation.

Fix

RCE

IDOR

Improper Authorization

Code Injection

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27823
GHSA-H9QX-V5XP-PH8P

Affected Products

Egroupware
Egroupware/Egroupware