CVE-2026-27823
A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker t
CVSS
—
Sin CVSS
EPSS
1.0%
p58
KEV
—
Exploit Today
17
0-100
Publicado: 20 jul 2026 · Última mod.: 20 jul 2026 · CWE-285
Sin historial EPSS suficiente todavía.
A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication. The vulnerability stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability, which together enable full system compromise. This has been patched in versions 26.2.20260224 and 23.1.20260224.