Junglewise Threat Intelligence

CVE-2026-45016: EGroupware Local File Inclusion in Mail Compose

CVE-2026-45016 · Severity: medium · CVSS 6.5 · Published 2026-07-07

Technologies: EGroupware.

Executive brief

EGroupware is a collaboration software suite used for email, calendaring, and document management. A security flaw in the email composition tool allows an authorized user to trick the server into reading sensitive files from its own storage. This could lead to the exposure of system passwords, database credentials, or private encryption keys, potentially compromising the entire server.

Technical details

A Local File Inclusion (LFI) vulnerability exists in EGroupware's mail composition logic within `api/src/Mail.php`. The application fails to properly validate URI schemes when processing image URLs in HTML email bodies. Specifically, the check `!str_starts_with($myUrl, 'http')` incorrectly permits `file://` URIs. When a user includes an `<img>` tag with a `file://` source, the server uses `file_get_contents()` to read the specified local file and attaches its contents as an inline MIME part in the outgoing email. This allows an authenticated attacker to exfiltrate sensitive files like `/etc/passwd` or configuration files. The issue is resolved in versions 26.5.20260507 and 23.1.20260601.

Affected products

  • EGroupware EGroupware >= 26.0.20251208, < 26.5.20260507; < 23.1.20260601

Timeline

  • 2026-07-07: advisory: GitHub Advisory GHSA-c8m7-r2jv-rw63 published
  • 2026-07-07: disclosed: Vulnerability disclosed with CVE-2026-45016

References