← Back to all sparks
E

EGroupware

COLLAB
Velocity5.0

Online groupware suite with calendar, contacts, projects and file management

EGroupware patches critical security vulnerabilities weekly while adding S/MIME certificate management.

groupwareemail-securitys-mimeenterpriseself-hosted
Current state
EGroupware is an enterprise groupware suite in heavy security-patch mode — five releases in six weeks have all led with security fixes rated high or critical. The 23.1 branch hit end-of-life in August 2026 with a final security release, consolidating the user base on 26.x. Outside the security cadence, the August 19 release added meaningful S/MIME improvements: CSR export/import, self-signed certificate generation, PKCS#7 upload support, and intermediate CA cert handling.
Where it's heading
With 23.1 EOL'd, development is concentrated on the 26.x branch. The S/MIME additions signal a deliberate push to strengthen email security credentials for compliance-sensitive enterprise users. The pace of security vulnerabilities being addressed is unusually high and may reflect active research against the codebase; once that subsides, the S/MIME track is the most visible direction for new capability.
Prediction
Security patch cadence should stabilize after the current vulnerability cluster is addressed. S/MIME groundwork points toward further email encryption additions — possibly PGP support or advanced certificate authority management — in the next 1-2 releases.

Recent moves

  1. 9d ago

    26.9.20260907

    Routine bug fixes: Australian address territory selection, calendar 6-month purge calculation, mail import upload failure, and a crash in send/draft when a referenced attachment's source message is missing. No security flag on this release — the first in several weeks.

    View source ↗
  2. 22d ago

    26.8: Critical security vulnerabilities patched

    Critical and multiple high-severity security vulnerabilities fixed. EGroupware's security advisories don't detail CVEs inline, but a 'critical' flag in a groupware product with calendar, mail, and addressbook access warrants immediate patching for any production deployment.

    View source ↗
  3. 28d ago

    23.1 final security release — branch now EOL

    Final security release for the 23.1 branch, patching multiple high-severity vulnerabilities before EOL. Users still on 23.1 are now without security coverage and need to migrate to 26.x.

    View source ↗
  4. 28d ago

    26.8: S/MIME CSR, self-signed certs, PKCS#7 support added

    Alongside security patches, this release ships a meaningful expansion of S/MIME capability: CSR export/import, self-signed certificate generation, PKCS#7/.cer upload support, intermediate CA certificate handling, and passphrase UX improvements. For organizations running email encryption in EGroupware, this closes gaps that previously required external certificate management tools.

    View source ↗
  5. 1mo ago

    26.8.20260811

    Security patch release fixes TypeErrors in OAuth Bearer token auth and OpenID token clearing on password reset. Calendar iCal import date handling also corrected. Three separate security fixes in this build indicate an active vulnerability disclosure process.

    View source ↗
  6. 1mo ago

    23.1.20260804

    Security patches plus a notice that 23.1 security coverage ends August 15, 2026 — pushing the final migration deadline for users on the legacy branch. Admin background image bug also corrected.

    View source ↗