Remote Code Execution Vulnerability in Group-Office by Intermesh
CVE-2026-25134
9.4CRITICAL
What is CVE-2026-25134?
Group-Office, an enterprise customer relationship management tool, contains a vulnerability where the MaintenanceController exposes a zipLanguage action. This action accepts a lang parameter, which is passed directly to a system zip command via exec(). If exploited, an attacker can upload a malicious zip file to execute arbitrary code on the server. This flaw has been resolved in versions 6.8.150, 25.0.82, and 26.0.5.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
groupoffice < 6.8.150 < 6.8.150
groupoffice >= 25.0.0, < 25.0.82 < 25.0.0, 25.0.82
groupoffice >= 26.0.0, < 26.0.5 < 26.0.0, 26.0.5
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
