CVE-2026-22243Disclosure(egroupware / egroupware)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.20260113, specifically in the `Nextmatch` filter processing. The flaw allows authenticated attackers to inject arbitrary SQL commands into the `WHERE` clause of database queries. This is achieved by exploiting a PHP type juggling issue where JSON decoding converts numeric strings into integers, bypassing the `is_int()` security check used by the application. Versions 23.1.20260113 and 26.0.20260113 patch the vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • egroupware

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
egroupware

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-01-28: 3Technical Details · 2026-01-28: 301-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-22243: Typecast Catastrophe: The EGroupware JSON-to-SQL Pipeline A high-severity SQL injection vulnerability in EGroupware's Nextmatch widget allows authenticated attackers to manipulate database queries via JSON type juggling. By leveraging ... https://cvereports.com/reports/CVE-2026-22243

    Post summary

    The text announces a high‑severity SQL injection flaw in EGroupware’s Nextmatch widget that exploits JSON type‑juggling, without providing PoC, patch, or exploitation details.

    0000047
    29 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22243 SQL Injection in EGroupware Core via PHP Type Juggling Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22243

    Post summary

    A new SQL injection vulnerability (CVE-2026-22243) affecting EGroupware Core due to PHP type juggling has been reported.

    0000040
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22243 EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 a… https://www.cve.org/CVERecord?id=CVE-2026-22243

    Post summary

    A SQL injection flaw exists in EGroupware before version 23.1.20260113, as identified by CVE-2026-22243.

    00000163
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appegroupwareegroupware---

Explore more