SQL Injection Vulnerability in Group-Office by Intermesh
CVE-2026-27832
What is CVE-2026-27832?
Group-Office, an enterprise customer relationship management and groupware tool, is impacted by a SQL Injection vulnerability that can be exploited through the advancedQueryData parameter in an authenticated environment. The vulnerability appears in versions prior to 26.0.8, 25.0.87, and 6.8.153, where the SQL comparator is processed without a stringent allowlist in the index.php?r=email/template/emailSelection endpoint. This oversight allows for blind boolean-based exfiltration of sensitive information, including data from the core_auth_password table. It is crucial for users of the affected versions to update to the latest releases to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
groupoffice < 6.8.153 < 6.8.153
groupoffice >= 25.0.0, < 25.0.87 < 25.0.0, 25.0.87
groupoffice >= 26.0.0, < 26.0.8 < 26.0.0, 26.0.8
