VYPR
High severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026

Authenticated RCE via Malicious eTemplate Upload in EGroupware

CVE-2026-40187

Description

In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (.xet) to the VFS /etemplates mount. The Widget::expand_name() method passes template widget attribute values directly into a PHP eval() call with only double-quote escaping applied - backtick characters are not escaped. In PHP, backticks inside a double-quoted eval() string execute shell commands. This allows an admin-level user to escalate from web application access to arbitrary OS command execution on the server.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
egroupware/egroupwarePackagist
>= 26.0.20251208, < 26.4.2026041326.4.20260413
egroupware/egroupwarePackagist
< 23.1.2026060123.1.20260601

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.