Skip to content

egroupware

v26.7.20260710 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 17d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

address-book caldav-server calendar carddav-server collaboration egroupware
+4 more
javascript php project-management webmail

ReleasePort's take

Moderate signal
editorial:auto 11d

The release patches several high‑severity security vulnerabilities and corrects critical bugs in Mail handling.

Why it matters: Security fact ID 70299 reports multiple high‑level vulnerabilities (severity 95) that must be patched; bugfix IDs 70300, 70302 address loss of recurrence data and access‑check failures affecting Calendar/Mail and Mail hooks.

Summary

AI summary

Updates Mail, Calendar/Mail, and Invoices across a mixed release.

Changes in this release

Security Critical

Fixes multiple high-level security vulnerabilities.

Fixes multiple high-level security vulnerabilities.

Source: llm_adapter@2026-07-15

Confidence: high

Feature Low

OCR import now identifies document type (invoice, credit note, ...) and billing period.

OCR import now identifies document type (invoice, credit note, ...) and billing period.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Removes "mail-display" prefix from Mail title display.

Removes "mail-display" prefix from Mail title display.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fixes access check issue in mail_hooks access method.

Fixes access check issue in mail_hooks access method.

Source: llm_adapter@2026-07-15

Confidence: high

Bugfix Medium

Fixes loss of recurrence end-date when applying external organizer updates in Calendar/Mail.

Fixes loss of recurrence end-date when applying external organizer updates in Calendar/Mail.

Source: llm_adapter@2026-07-15

Confidence: low

Bugfix Low

Inserting custom fields removes most data from existing fields in all apps.

Inserting custom fields removes most data from existing fields in all apps.

Source: granite4.1:30b@2026-07-15-audit

Confidence: low

Full changelog
  • SECURITY: this release fixes multiple high level security vulnerabilities, everyone is strongly adviced to update to it!
  • All apps: inserting a new custom-fields between or before existing ones removes most data from the existing fields
  • Calendar/Mail: fix applying an external organizers update did loose the recurrence end-date
  • Mail: display title no longer shows "mail-display" prefix
  • Mail: fix access check in mail_hooks access method
  • Invoices: OCR import now identifies document type (invoice, credit note, ...) and billing period

Security Fixes

  • Multiple high‑level security vulnerabilities fixed; all users strongly advised to update.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track egroupware

Get notified when new releases ship.

Sign up free

About egroupware

Software suite including calendars, address books, notepad, project management tools, client relationship management tools (CRM), knowledge management tools, a wiki and a CMS.

All releases →

Related context

Beta — feedback welcome: [email protected]