Remote Code Execution Vulnerability in Group-Office by Intermesh
CVE-2026-25134

9.4CRITICAL

Key Information:

Vendor

Intermesh

Vendor
CVE Published:
2 February 2026

What is CVE-2026-25134?

Group-Office, an enterprise customer relationship management tool, contains a vulnerability where the MaintenanceController exposes a zipLanguage action. This action accepts a lang parameter, which is passed directly to a system zip command via exec(). If exploited, an attacker can upload a malicious zip file to execute arbitrary code on the server. This flaw has been resolved in versions 6.8.150, 25.0.82, and 26.0.5.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

groupoffice < 6.8.150 < 6.8.150

groupoffice >= 25.0.0, < 25.0.82 < 25.0.0, 25.0.82

groupoffice >= 26.0.0, < 26.0.5 < 26.0.0, 26.0.5

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.