High severityNVD Advisory· Published Jul 20, 2026· Updated Jul 20, 2026
Authenticated RCE via Malicious eTemplate Upload in EGroupware
CVE-2026-40187
Description
In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (.xet) to the VFS /etemplates mount. The Widget::expand_name() method passes template widget attribute values directly into a PHP eval() call with only double-quote escaping applied - backtick characters are not escaped. In PHP, backticks inside a double-quoted eval() string execute shell commands. This allows an admin-level user to escalate from web application access to arbitrary OS command execution on the server.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
egroupware/egroupwarePackagist | >= 26.0.20251208, < 26.4.20260413 | 26.4.20260413 |
egroupware/egroupwarePackagist | < 23.1.20260601 | 23.1.20260601 |
Affected products
1- Range: <=26.0
Patches
Vulnerability mechanics
References
2- github.com/advisories/GHSA-8737-2x9g-xjj7ghsaADVISORY
- github.com/EGroupware/egroupware/security/advisories/GHSA-8737-2x9g-xjj7ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.