CVE-2026-25134Disclosure(group-office / group_office)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch group-office group_office systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip file to achieve remote code execution. This vulnerability is fixed in 6.8.150, 25.0.82, and 26.0.5.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • group_office

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-02); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
group_office

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-02-02: 2Mentions · 2026-02-03: 2Mentions · 2026-02-04: 1Mentions · 2026-03-02: 1PoC Mentioned / Linked · 2026-02-02: 1Patch / Workaround · 2026-02-02: 1Technical Details · 2026-02-02: 2Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 102-0202-0302-0403-02
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-022
Disclosure2
2026-02-032
Disclosure2
2026-02-041
Disclosure1
2026-03-021
General1
Full discourse6 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical RCE in #Intermesh #Group-Office #CRM (CVE-2026-25134, CVSS 9.4). Attackers can abuse the zipLanguage action with a crafted ZIP to achieve remote code execution. More info: https://github.com/Intermesh/groupoffice/security/advisories/GHSA-v39j-549w-8849 #RCE! #Patch #Patch #Patch

    Post summary

    The post announces a critical RCE vulnerability (CVE-2026-25134) in Intermesh Group-Office CRM, describing the exploit vector via a crafted ZIP file, but provides no evidence of active exploitation or patch details.

    01010277
    7.2K followersView on X
  • David@DavidMarquet19
    General

    📌 Top CVEs recientes (CVSS>=7.0): 1. 🛡️ CVE-2026-25221 (CVSS: 8.1) 2. ⚠️ CVE-2026-25134 (CVSS: 8.8) 3. ⚠️ CVE-2026-23515 (CVSS: 9.9) 4. 🕷️ CVE-2025-13096 (CVSS: 7.1) 5. ⚠️ CVE-2026-22229 (CVSS: 7.2) #CyberSecurity #CVE #Infosec

    Post summary

    A brief list of recent high‑CVSS CVEs with no additional context or actionable information.

    0000076
    167 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    ⚠️⚠️⚠️ 『an authenticated attacker (with basic user privileges) can execute arbitrary commands on the server.』 CVE-2026-25134 Remote Code Execution (RCE) · Advisory · Intermesh/groupoffice · GitHub https://github.com/Intermesh/groupoffice/security/advisories/GHSA-v39j-549w-8849

    Post summary

    The advisory announces CVE‑2026‑25134, a Remote Code Execution flaw in Intermesh GroupOffice that allows an authenticated basic user to run arbitrary commands on the server; no PoC, exploit code, or patch details are provided.

    00000465
    6.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25134 Remote Code Execution in Group-Office via Unsanitized Language Parameter Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25134

    Post summary

    The post announces CVE-2026-25134, highlighting a remote code execution vulnerability in Group-Office caused by unsanitized language parameter handling.

    0000067
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25134 Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action … https://www.cve.org/CVERecord?id=CVE-2026-25134

    Post summary

    The text announces CVE‑2026‑25134, describing a vulnerable action in Group‑Office's MaintenanceController and indicating that versions 6.8.150, 25.0.82, and 26.0.5 contain the patch.

    00000126
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25134: Group-Office Argument Injection ... Classic command injection in exec() via unfiltered 'lang' parameter leads to full RCE - just upload a crafted zip and g... https://zerodaysignal.com/vulnerability/CVE-2026-25134 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑25134, describing a classic command injection in Group‑Office’s exec() function via the unfiltered ‘lang’ parameter that allows full RCE through a crafted zip file, with no patches or active exploitation reported but providing technical details of the flaw.

    0000063
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgroup-officegroup_office---

Explore more