OS-Level Remote Code Execution Vulnerability in EGroupware by EGroupware
CVE-2026-40187

8.6HIGH

Key Information:

Vendor

Egroupware

Vendor
CVE Published:
20 July 2026

What is CVE-2026-40187?

In EGroupware versions 26.0 and earlier, an authenticated administrator can exploit a significant security vulnerability by uploading a malicious eTemplate XML file to the Virtual File System. The application's Widget::expand_name() method inadequately handles user input, specifically not escaping backtick characters when combined with a PHP eval() function. This flaw enables an admin user with access to the web application to execute arbitrary commands directly on the operating system, thereby escalating their privilege from web application access to complete command execution control over the server.

Affected Version(s)

egroupware <= 26.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.