EGroupware
cpe:2.3:a:egroupware:egroupware:*:*:*:*:*:*:*
- <= 26.2.20260216
- <= 23.1.20260131
A remote code execution vulnerability has been identified in EGroupware versions through 26.2.20260216 and 23.1.20260131. This vulnerability allows authenticated attackers to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication. The issue arises from improper authorization checks, combined with a file write primitive and an arbitrary file read vulnerability, enabling full system compromise.
Exploitation of this vulnerability leads to remote code execution, full system compromise, and a potential complete takeover of the EGroupware instance.
The vulnerability can be reproduced by sending a crafted request that manipulates the 'participant_role' value to bypass authorization checks. Once the 'isTeacher' check is bypassed, files can be uploaded to a controllable file path, such as './header.inc.php'. After uploading a PHP web shell, the file can be overwritten with modified content to inject controlled PHP code, which will be executed after a server restart or OPcache expiration. Alternatively, the admin setup password can be modified to gain full control over the EGroupware instance.
Users can update to EGroupware versions 26.2.20260224 or 23.1.20260224 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.