CVE-2026-27823
Received Received - Intake

Remote Code Execution in EGroupware

Vulnerability report for CVE-2026-27823, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: GitHub, Inc.

Description

A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication. The vulnerability stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability, which together enable full system compromise. This has been patched in versions 26.2.20260224 and 23.1.20260224.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
egroupware egroupware 26.2.20260224
egroupware egroupware 23.1.20260224
egroupware egroupware to 26.2.20260216 (exc)
egroupware egroupware to 23.1.20260131 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a critical Remote Code Execution (RCE) vulnerability in EGroupware. It allows authenticated attackers to execute arbitrary commands on the server. If user self-registration is enabled, unauthenticated attackers can exploit it. The flaw comes from improper authorization checks, combined with file write and read vulnerabilities, enabling full system compromise.

Detection Guidance

Check if your EGroupware version is below 26.2.20260224 or 23.1.20260224. Inspect server logs for unusual file uploads or modifications to header.inc.php. Look for unauthorized access attempts or unexpected PHP code execution.

Impact Analysis

An attacker could gain full control of the server, steal sensitive data, install malware, or disrupt services. If self-registration is enabled, attackers may exploit it without needing an account. The vulnerability allows arbitrary command execution, leading to severe system compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality. A successful exploit may result in data breaches, triggering legal penalties and compliance violations.

Mitigation Strategies

Upgrade EGroupware to versions 26.2.20260224 or 23.1.20260224 immediately. Disable user self-registration if enabled. Restrict file write permissions for the server process. Monitor for signs of compromise and review admin credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27823. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart