PT-2026-56210 · Egroupware+1 · Egroupware+1
CVE-2026-27823
·
Published
2026-07-07
·
Updated
2026-07-21
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
EGroupware versions prior to 26.2.20260224
EGroupware versions prior to 23.1.20260224
Description
An issue allows an authenticated attacker to execute arbitrary commands on the server, which may lead to full system compromise. If user self-registration is enabled, the issue can be exploited without prior authentication. The flaw results from improper authorization checks combined with an arbitrary file read and a file write primitive. Specifically, the
ajax upload() function in EGroupwareSmallParTWidgetsSmallPartMediaRecorder fails to properly validate the participant role variable, which is derived from user-controlled request data, allowing attackers to bypass teacher role checks. This enables an arbitrary file write via the video type variable, allowing path traversal to overwrite files such as header.inc.php. Additionally, the download function in importexport export ui is susceptible to arbitrary file read through the filename parameter. By combining these flaws, an attacker can read a valid system file, modify it with malicious PHP code, and overwrite it to achieve Remote Code Execution (RCE) upon server restart or OPcache expiration.Recommendations
Update EGroupware to version 26.2.20260224 or later.
Update EGroupware to version 23.1.20260224 or later.
As a temporary mitigation, disable user self-registration to prevent unauthenticated exploitation.
Fix
RCE
IDOR
Improper Authorization
Code Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Egroupware
Egroupware/Egroupware