SQL Injection Vulnerability in Group-Office by Intermesh
CVE-2026-27832

7.1HIGH

Key Information:

Vendor

Intermesh

Vendor
CVE Published:
27 February 2026

What is CVE-2026-27832?

Group-Office, an enterprise customer relationship management and groupware tool, is impacted by a SQL Injection vulnerability that can be exploited through the advancedQueryData parameter in an authenticated environment. The vulnerability appears in versions prior to 26.0.8, 25.0.87, and 6.8.153, where the SQL comparator is processed without a stringent allowlist in the index.php?r=email/template/emailSelection endpoint. This oversight allows for blind boolean-based exfiltration of sensitive information, including data from the core_auth_password table. It is crucial for users of the affected versions to update to the latest releases to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

groupoffice < 6.8.153 < 6.8.153

groupoffice >= 25.0.0, < 25.0.87 < 25.0.0, 25.0.87

groupoffice >= 26.0.0, < 26.0.8 < 26.0.0, 26.0.8

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.