CVE-2026-34838

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directly to Remote Code Execution (RCE) on the server. This issue has been patched in versions 6.8.156, 25.0.90, and 26.0.12.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:*
cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:*
cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:*

History

15 Apr 2026, 17:29

Type Values Removed Values Added
References () https://github.com/Intermesh/groupoffice/releases/tag/v25.0.90 - () https://github.com/Intermesh/groupoffice/releases/tag/v25.0.90 - Release Notes
References () https://github.com/Intermesh/groupoffice/releases/tag/v26.0.12 - () https://github.com/Intermesh/groupoffice/releases/tag/v26.0.12 - Release Notes
References () https://github.com/Intermesh/groupoffice/releases/tag/v6.8.156 - () https://github.com/Intermesh/groupoffice/releases/tag/v6.8.156 - Release Notes
References () https://github.com/Intermesh/groupoffice/security/advisories/GHSA-h22j-frrf-5vxq - () https://github.com/Intermesh/groupoffice/security/advisories/GHSA-h22j-frrf-5vxq - Vendor Advisory
CPE cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:*
First Time Intermesh
Intermesh group-office

02 Apr 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-02 20:16

Updated : 2026-04-15 17:29


NVD link : CVE-2026-34838

Mitre link : CVE-2026-34838

CVE.ORG link : CVE-2026-34838


JSON object : View

Products Affected

intermesh

  • group-office
CWE
CWE-502

Deserialization of Untrusted Data