PatchSiren

EGroupware CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH EGroupware CVE published 2026-07-20

CVE-2026-27823

CVE-2026-27823 is a high-severity vulnerability in EGroupware that allows authenticated attackers to execute arbitrary commands on the server, potentially leading to full system compromise. The issue stems from improper authorization checks combined with a file write primitive and an arbitrary file read vulnerability. If user self-registration is enabled, the vulnerability may be exploitable without prior [truncated]