← Vulnerability feed

Vulnerability record · CVE-2026-25134 · published 2 February 2026

CVE-2026-25134: Group-office group office argument injection vulnerability

Group Office · Group Office

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip file to achieve remote code execution. This vulnerability is fixed in 6.8.150, 25.0.82, and 26.0.5.

9.4 CVSS 4.0 Critical EPSS 0.85% · top 43.6% CWE-88 · Argument injection
9.4CVSS 4.0 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip file to achieve remote code execution. This vulnerability is fixed in 6.8.150, 25.0.82, and 26.0.5.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25134 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-25512Group-office group office os command injection vulnerabilityGroup-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote …EPSS 3.5%8.8CVE-2025-63406Group-office group office command injection vulnerabilityAn issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and…EPSS 0.74%8.8CVE-2023-46730Group-office group office server-side request forgery (ssrf) vulnerabilityGroup-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api…EPSS 0.60%8.2CVE-2026-25511Group-office group office server-side request forgery (ssrf) vulnerabilityGroup-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, an authenticated u…EPSS 0.43%6.9CVE-2025-25191Group-office group office cross-site scripting vulnerabilityGroup-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitiz…EPSS 0.28%6.1CVE-2023-25292Group-office group office cross-site scripting vulnerabilityReflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive i…EPSS 0.59%6.1CVE-2020-35419Group-office group office cross-site scripting vulnerabilityCross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.EPSS 0.67%5.4CVE-2024-23941Group-office group office cross-site scripting vulnerabilityCross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenti…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2026-25134), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.