CVE-2026-22243·PHP vulnerability
EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.20260113, specifically in the `Nextmatch` filter processing. The flaw allows authenticated attackers to inject arbitrary SQL commands into the `WHERE` clause of database queries. This is achieved by exploiting a PHP type juggling issue where JSON decoding converts numeric strings into integers, bypassing the `is_int()` security check used by the application. Versions 23.1.20260113 and 26.0.20260113 patch the vulnerability.
- Severity
- high
- Software
- PHP
- Fixed in
- 26.0.20260113
- Published
- 2026-01-28
Affected versions
From: 26.0.20251208
Until: 26.0.20260113
Fixed in: 26.0.20260113
How to fix this CVE
Update EGroupware to version 26.0.20260113 or later to patch the SQL injection vulnerability in the Nextmatch filter processing component. This fix addresses a type juggling flaw that allowed authenticated users to bypass integer validation checks and inject malicious SQL commands. Ensure all PHP-based EGroupware instances are upgraded immediately, as the vulnerability requires valid authentication but provides high-impact database access.
sudo dnf update phpDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /egroupware/index.php with filter parameters containing numeric type-juggling payloads in the WHERE clause (e.g., filter values like '1 OR 1=1' or '1 AND (SELECT...' following JSON decoding that bypasses is_int() checks)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement WAF rules to detect and block POST requests to EGroupware filter endpoints containing SQL keywords (UNION, SELECT, INSERT, DROP, OR, AND) in filter parameter values, and enforce strict input validation on all filter and search parameters to reject non-integer values that should be numeric.How to check if you are affected
- Check PHP version with: php -v
- Identify EGroupware installation directory: find / -name 'egroupware' -type d 2>/dev/null
- Verify EGroupware version from: cat /path/to/egroupware/setup/version.inc.php | grep -i version
- Review web server access logs for POST requests to filter or search endpoints containing unusual WHERE clause patterns: grep -i 'nextmatch\|filter' /var/log/apache2/access.log | grep POST
- Check for SQL error messages in application logs: grep -i 'sql\|syntax error' /var/log/egroupware/*.log
FAQ
What is CVE-2026-22243?
CVE-2026-22243 is a SQL injection vulnerability in EGroupware's Nextmatch filter feature that exploits PHP type juggling to bypass integer validation, allowing authenticated attackers to execute arbitrary SQL commands against the database.
Is CVE-2026-22243 being actively exploited?
No, according to CISA KEV data, CVE-2026-22243 is not currently listed as actively exploited in the wild, and no public exploit code is available.
What versions of PHP and EGroupware are affected by CVE-2026-22243?
EGroupware versions 26.0.20251208 through 26.0.20260112 are vulnerable; the fix is available in 26.0.20260113 and later, as well as version 23.1.20260113.
How do I check if my server is vulnerable to CVE-2026-22243?
Run: cat /path/to/egroupware/setup/version.inc.php | grep -i version, then compare against the affected range (26.0.20251208 to 26.0.20260112). If your version falls in this range, your server is vulnerable.
Can unauthenticated users exploit CVE-2026-22243?
No, CVE-2026-22243 requires valid EGroupware authentication credentials to exploit, limiting the attack surface to authenticated users only.
Does Defensia detect CVE-2026-22243?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP and EGroupware are installed on a monitored server, CVE-2026-22243 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-22243. Free for 1 server.
Get started free