CVE Explorer
CVE-2026-27823
A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior authentication. The vulnerability stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability, which together enable full system compromise. This has been patched in ve
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"egroupware","vendor":"EGroupware","versions":[{"status":"affected","version":"<= 26.2.20260216"},{"status":"affected","version":"<= 23.1.20260131"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0ee5d41c765bbaa46728d68a64e04188d2ab6ea58d09519eeebeb2bde2f6354a · sha256:0eecb1e8408dbbfd… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0ee5d41c765bbaa46728d68a64e04188d2ab6ea58d09519eeebeb2bde2f6354a · sha256:0eecb1e8408dbbfd… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-285","description":"CWE-285: Improper Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0ee5d41c765bbaa46728d68a64e04188d2ab6ea58d09519eeebeb2bde2f6354a · sha256:0eecb1e8408dbbfd… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/EGroupware/egroupware/security/advisories/GHSA-h9qx-v5xp-ph8p","tags":["x_refsource_CONFIRM"],"url":"https://github.com/EGroupware/egroupware/security/advisories/GHSA-h9qx-v5xp-ph8p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0ee5d41c765bbaa46728d68a64e04188d2ab6ea58d09519eeebeb2bde2f6354a · sha256:0eecb1e8408dbbfd… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.