CVE-2026-22243: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-22243 is a SQL Injection vulnerability in EGroupware's Nextmatch filter processing component, allowing authenticated attackers to inject arbitrary SQL commands into database query WHERE clauses. It affects EGroupware Community Edition versions prior to 23.1.20260113 and versions 26.0.20251208 through 26.0.20260113 (prior to 26.0.20260113). The vulnerability was reported by Łukasz Rybak, published on January 28, 2026, and patched the same day. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (Github Advisory, EGroupware Advisory).

Technical details

The root cause is a PHP type juggling issue (CWE-89) in the database abstraction layer (Api\Db) and storage classes (Api\Storage\Base, infolog_so) that process the col_filter array in Nextmatch widgets. The application uses is_int($key) to determine whether an array key represents a trusted raw SQL fragment; however, PHP's json_decode() automatically converts numeric string keys (e.g., "0") into native integers, causing is_int() to return true. An attacker can craft a JSON POST payload with numeric-keyed associative arrays containing malicious SQL, which is then appended directly to the query without sanitization in column_data_implode (Db.php ~line 1776) and parse_search (Storage/Base.php ~line 1134). The attack is delivered over the network via the json.php endpoint (EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows) and requires only low-privilege authentication (EGroupware Advisory, Github Advisory).

Impact

Successful exploitation allows authenticated attackers with low-privilege accounts to fully compromise the EGroupware database, resulting in high confidentiality, integrity, and availability impact. Attackers can read sensitive data including password hashes, session tokens, personal contact details, and configuration secrets; modify or delete arbitrary application data; and potentially drop tables or corrupt data. The vulnerability was confirmed exploitable on the public demo.egroupware.net instance, indicating real-world exposure for any internet-facing EGroupware deployment (EGroupware Advisory).

Exploitability

A public proof-of-concept exploit script (Python-based, automating login, exec_id extraction, and error-based SQL injection via EXTRACTVALUE) is available in the GitHub Security Advisory and was confirmed working against the EGroupware public demo instance. The exploit was also indexed by Sploitus. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.028% (0.000280), placing it in a low exploitation probability tier (Github Advisory, EGroupware Advisory).

Exploitation steps

  1. Authenticate: Obtain valid credentials for any low-privilege EGroupware account. Use the login endpoint (/login.php) with a POST request containing login, passwd, and submitit parameters to establish an authenticated session.
  2. Retrieve exec_id: Send a GET request to /index.php?menuaction=addressbook.addressbook_ui.index and parse the HTML response to extract the etemplate_exec_id value using a regex pattern (e.g., etemplate_exec_id\s*:\s*"([^&"\\]+)").
  3. Craft malicious JSON payload: Construct a JSON POST body targeting the vulnerable endpoint /json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows. Include a col_filter object with a numeric key ("0") whose value contains an error-based SQL injection payload, e.g.:
    {"request": {"parameters": ["<exec_id>", {"start": 0, "num_rows": 1}, {"col_filter": {"0": "1=1 AND EXTRACTVALUE(1, CONCAT(0x7e, (SELECT @@version), 0x7e))"}}]}}
  4. Exploit type juggling: PHP's json_decode() converts the numeric string key "0" to an integer, causing is_int() to return true. The malicious SQL value is appended unsanitized to the database query's WHERE clause.
  5. Extract data: Parse the server's error response for the XPATH syntax error pattern (e.g., ~<data>~) to retrieve exfiltrated data. Iterate with SUBSTRING() offsets to extract longer strings. Target sensitive tables such as egw_accounts to retrieve password hashes (SELECT CONCAT(account_lid,':',account_pwd) FROM egw_accounts WHERE account_lid='sysop') (EGroupware Advisory, Github Advisory).

Indicators of compromise

  • Network: Unusual JSON POST requests to /json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows containing col_filter objects with numeric keys ("0", "1", etc.) and SQL keywords (EXTRACTVALUE, CONCAT, SUBSTRING, SELECT, UNION).
  • Network: Repeated GET requests to /index.php?menuaction=addressbook.addressbook_ui.index from the same session immediately followed by POST requests to json.php (indicative of automated exec_id harvesting).
  • Logs: Web server access logs showing HTTP 200 responses to json.php with request bodies containing SQL functions such as EXTRACTVALUE, CONCAT(0x7e, or @@version.
  • Logs: Database error logs containing XPATH syntax errors (e.g., XPATH syntax error: '~<data>~') triggered by EXTRACTVALUE-based injection payloads.
  • Logs: Application logs showing repeated authentication from the same IP followed by rapid sequential API calls to the Nextmatch AJAX endpoint.
  • File System: Presence of automated exploit scripts (Python files referencing egroupware, exec_id, EXTRACTVALUE, col_filter) on attacker-controlled systems or in web-accessible directories if the server was further compromised (EGroupware Advisory).

Mitigation and workarounds

Upgrade EGroupware immediately to version 23.1.20260113 (for the 23.1 branch) or 26.0.20260113 (for the 26.0 branch), both released January 13, 2026, and designated as SECURITY and Maintenance Releases with a strong recommendation for immediate update. No configuration-based workaround is provided by the vendor; patching is the only supported remediation. As interim measures, restrict EGroupware access to trusted networks via firewall rules, enforce strong authentication policies, and monitor database query logs for anomalous SQL patterns such as EXTRACTVALUE or CONCAT(0x7e (EGroupware Release 23.1, EGroupware Release 26.0, Github Advisory).

Community reactions

The vulnerability was reported by security researcher Łukasz Rybak and disclosed responsibly through GitHub's security advisory process. EGroupware maintainer ralfbecker published the advisory and patched releases on January 13 and 28, 2026, with a strong recommendation for immediate updates. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database indexing (EGroupware Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management