Back to search
CVE-2026-25134
Published: Feb 2, 2026
Modified: Feb 4, 2026
PUBLISHED
Description
Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip file to achieve remote code execution. This vulnerability is fixed in 6.8.150, 25.0.82, and 26.0.5.
| Vendor | Product | Versions |
|---|---|---|
Intermesh | groupoffice | affected < 6.8.150affected >= 25.0.0, < 25.0.82affected >= 26.0.0, < 26.0.5 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now