
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22243 is a SQL Injection vulnerability in EGroupware's Nextmatch filter processing component, allowing authenticated attackers to inject arbitrary SQL commands into database query WHERE clauses. It affects EGroupware Community Edition versions prior to 23.1.20260113 and versions 26.0.20251208 through 26.0.20260113 (prior to 26.0.20260113). The vulnerability was reported by Łukasz Rybak, published on January 28, 2026, and patched the same day. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (Github Advisory, EGroupware Advisory).
The root cause is a PHP type juggling issue (CWE-89) in the database abstraction layer (Api\Db) and storage classes (Api\Storage\Base, infolog_so) that process the col_filter array in Nextmatch widgets. The application uses is_int($key) to determine whether an array key represents a trusted raw SQL fragment; however, PHP's json_decode() automatically converts numeric string keys (e.g., "0") into native integers, causing is_int() to return true. An attacker can craft a JSON POST payload with numeric-keyed associative arrays containing malicious SQL, which is then appended directly to the query without sanitization in column_data_implode (Db.php ~line 1776) and parse_search (Storage/Base.php ~line 1134). The attack is delivered over the network via the json.php endpoint (EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows) and requires only low-privilege authentication (EGroupware Advisory, Github Advisory).
Successful exploitation allows authenticated attackers with low-privilege accounts to fully compromise the EGroupware database, resulting in high confidentiality, integrity, and availability impact. Attackers can read sensitive data including password hashes, session tokens, personal contact details, and configuration secrets; modify or delete arbitrary application data; and potentially drop tables or corrupt data. The vulnerability was confirmed exploitable on the public demo.egroupware.net instance, indicating real-world exposure for any internet-facing EGroupware deployment (EGroupware Advisory).
A public proof-of-concept exploit script (Python-based, automating login, exec_id extraction, and error-based SQL injection via EXTRACTVALUE) is available in the GitHub Security Advisory and was confirmed working against the EGroupware public demo instance. The exploit was also indexed by Sploitus. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.028% (0.000280), placing it in a low exploitation probability tier (Github Advisory, EGroupware Advisory).
/login.php) with a POST request containing login, passwd, and submitit parameters to establish an authenticated session.exec_id: Send a GET request to /index.php?menuaction=addressbook.addressbook_ui.index and parse the HTML response to extract the etemplate_exec_id value using a regex pattern (e.g., etemplate_exec_id\s*:\s*"([^&"\\]+)")./json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows. Include a col_filter object with a numeric key ("0") whose value contains an error-based SQL injection payload, e.g.:{"request": {"parameters": ["<exec_id>", {"start": 0, "num_rows": 1}, {"col_filter": {"0": "1=1 AND EXTRACTVALUE(1, CONCAT(0x7e, (SELECT @@version), 0x7e))"}}]}}json_decode() converts the numeric string key "0" to an integer, causing is_int() to return true. The malicious SQL value is appended unsanitized to the database query's WHERE clause.~<data>~) to retrieve exfiltrated data. Iterate with SUBSTRING() offsets to extract longer strings. Target sensitive tables such as egw_accounts to retrieve password hashes (SELECT CONCAT(account_lid,':',account_pwd) FROM egw_accounts WHERE account_lid='sysop') (EGroupware Advisory, Github Advisory)./json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows containing col_filter objects with numeric keys ("0", "1", etc.) and SQL keywords (EXTRACTVALUE, CONCAT, SUBSTRING, SELECT, UNION)./index.php?menuaction=addressbook.addressbook_ui.index from the same session immediately followed by POST requests to json.php (indicative of automated exec_id harvesting).json.php with request bodies containing SQL functions such as EXTRACTVALUE, CONCAT(0x7e, or @@version.XPATH syntax error: '~<data>~') triggered by EXTRACTVALUE-based injection payloads.egroupware, exec_id, EXTRACTVALUE, col_filter) on attacker-controlled systems or in web-accessible directories if the server was further compromised (EGroupware Advisory).Upgrade EGroupware immediately to version 23.1.20260113 (for the 23.1 branch) or 26.0.20260113 (for the 26.0 branch), both released January 13, 2026, and designated as SECURITY and Maintenance Releases with a strong recommendation for immediate update. No configuration-based workaround is provided by the vendor; patching is the only supported remediation. As interim measures, restrict EGroupware access to trusted networks via firewall rules, enforce strong authentication policies, and monitor database query logs for anomalous SQL patterns such as EXTRACTVALUE or CONCAT(0x7e (EGroupware Release 23.1, EGroupware Release 26.0, Github Advisory).
The vulnerability was reported by security researcher Łukasz Rybak and disclosed responsibly through GitHub's security advisory process. EGroupware maintainer ralfbecker published the advisory and patched releases on January 13 and 28, 2026, with a strong recommendation for immediate updates. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database indexing (EGroupware Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."