{"id":"CVE-2026-22243","aliases":["GHSA-rvxj-7f72-mhrx"],"url":"https://o3.security/vulnerability/CVE-2026-22243","summary":"EGroupware has SQL Injection in Nextmatch Filter Processing","details":"EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components of EGroupware prior to versions 23.1.20260113 and 26.0.20260113, specifically in the `Nextmatch` filter processing. The flaw allows authenticated attackers to inject arbitrary SQL commands into the `WHERE` clause of database queries. This is achieved by exploiting a PHP type juggling issue where JSON decoding converts numeric strings into integers, bypassing the `is_int()` security check used by the application. Versions 23.1.20260113 and 26.0.20260113 patch the vulnerability.","published":"2026-01-28T16:05:35.641Z","modified":"2026-08-12T03:51:32.496522790Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"egroupware/egroupware","fixedVersion":"23.1.20260113"},{"ecosystem":"Packagist","name":"egroupware/egroupware","fixedVersion":"26.0.20260113"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/EGroupware/egroupware/releases/tag/23.1.20260113"},{"type":"WEB","url":"https://github.com/EGroupware/egroupware/releases/tag/26.0.20260113"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22243.json"},{"type":"ADVISORY","url":"https://github.com/EGroupware/egroupware/security/advisories/GHSA-rvxj-7f72-mhrx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22243"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.496522790Z"}}