CVE-2026-33755Patch(intermesh / group-office)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch intermesh group-office systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `Contact/query` endpoint allows any authenticated user with basic addressbook access to extract arbitrary data from the database — including active session tokens of other users. This enables full account takeover of any user, including the System Administrator, without knowing their password. Versions 6.8.158, 25.0.92, and 26.0.17 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • group-office

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-27); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
group-office

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 103-2703-28
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-271
Patch1
2026-03-281
Disclosure1
Full discourse2 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33755 - High Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `C... https://www.thehackerwire.com/vulnerability/CVE-2026-33755/ https://t.co/qbwa2J6I1w

    Post summary

    The tweet announces CVE-2026-33755, an authenticated SQL injection in Group-Office’s JMAP interface affecting specific older versions.

    0000041
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33755: HIGH] Update Group-Office to versions 6.8.158, 25.0.92, or 26.0.17 to protect against an SQL Injection vulnerability allowing unauthorized access to sensitive data.#cve,CVE-2026-33755,#cybersecurity https://cvefind.com/CVE-2026-33755

    Post summary

    An advisory recommends updating to specific Group-Office versions to mitigate a high‑severity SQL injection vulnerability.

    0000037
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appintermeshgroup-office---

Explore more