CVE-2026-34838Disclosure(intermesh / group-office)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch intermesh group-office systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directly to Remote Code Execution (RCE) on the server. This issue has been patched in versions 6.8.156, 25.0.90, and 26.0.12.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • group-office

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-04-02); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
group-office

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-03: 2Mentions · 2026-04-06: 1Mentions · 2026-04-07: 1Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-02: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-11: 104-0204-0304-0604-0704-11
Signal classification3 categories
Disclosure
342.9%
Patch
228.6%
General
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure1Patch1
2026-04-032
Disclosure2
2026-04-061
Patch1
2026-04-071
General1
2026-04-111
General1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Patch

    CVE-2026-34838: A critical 10.0 flaw in GroupOffice allows authenticated users to trigger RCE via insecure deserialization. Update to v26.0.12 immediately! #GroupOffice #CyberSecurity #InfoSec #RCE #PHPSecurity #CVE202634838 #BugBounty #CRM https://securityonline.info/groupoffice-cve-2026-34838-insecure-deserialization-rce/ https://t.co/iuVKyjYaSd

    Post summary

    The tweet announces CVE‑2026‑34838, a critical RCE via insecure deserialization in GroupOffice, and urges users to update to v26.0.12 immediately.

    04060572
    12.3K followersView on X
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-34838 · NIST 9.9/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34838

    Post summary

    The text merely references CVE‑2026‑34838 with its NIST rating and provides a link to the NVD entry, offering no further details.

    1000024
    1 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-34838: Group-Office Insecure Deserialization Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04bsJRV0

    Post summary

    The text announces CVE-2026-34838 as an insecure deserialization vulnerability, but provides no PoC, exploit details, or mitigation advice.

    0000032
    28 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34838 Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSet… https://www.cve.org/CVERecord?id=CVE-2026-34838

    Post summary

    The post announces CVE‑2026‑34838, noting that Group‑Office versions prior to 6.8.156, 25.0.90, and 26.0.12 are affected by a vulnerability in the AbstractSet component, with details available via the linked CVE record.

    00000114
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34838 - Critical Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model... https://www.thehackerwire.com/vulnerability/CVE-2026-34838/ https://t.co/nBdQSgrylN

    Post summary

    A critical vulnerability in Group-Office’s AbstractSettingsCollection model has been disclosed, but the post lacks any PoC, exploit code, or patch details.

    0000051
    160 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34838: CRITICAL] A critical cyber security vulnerability in Group-Office allows an authenticated attacker to achieve Remote Code Execution. Ensure you update to versions 6.8.156, 25.0.90, or 26.0.1...#cve,CVE-2026-34838,#cybersecurity https://cvefind.com/CVE-2026-34838

    Post summary

    The post announces a critical RCE vulnerability (CVE‑2026‑34838) in Group‑Office and advises users to upgrade to patched versions.

    0000075
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34838: Group-Office: Authenticated Remo... FileCookieJar deserialization in Group-Office settings = instant RCE with just auth - PHP object injection doesn't get ... https://zerodaysignal.com/vulnerability/CVE-2026-34838 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-34838, a Group‑Office vulnerability that allows authenticated users to achieve remote code execution through PHP object injection via FileCookieJar deserialization, and provides a link for further information.

    0000092
    193 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appintermeshgroup-office---

Explore more