This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+4 more
ReleasePort's take
Moderate signalThe release fixes multiple high‑level security vulnerabilities.
Why it matters: Addresses high‑severity (severity 90) system‑wide security issues; operators should apply the update promptly to mitigate risk.
Summary
AI summaryMultiple high‑level security vulnerabilities are fixed.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes multiple high-level security vulnerabilities. Fixes multiple high-level security vulnerabilities. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes access check in mail_hooks access method. Fixes access check in mail_hooks access method. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Inserting new custom fields removes most data from existing fields. Inserting new custom fields removes most data from existing fields. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
- SECURITY: this release fixes multiple high level security vulnerabilities, everyone is strongly adviced to update to it!
- This is probably the last 23.1 security release, we recommend to update to 26.x rather sooner than later.
- All apps: inserting a new custom-fields between or before existing ones removes most data from the existing fields
- Mail: fix access check in mail_hooks access method
Security Fixes
- Multiple high‑level security vulnerabilities fixed (details not specified).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About egroupware
Software suite including calendars, address books, notepad, project management tools, client relationship management tools (CRM), knowledge management tools, a wiki and a CMS.
Beta — feedback welcome: [email protected]