CVE-2026-34838 Details
Description
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directly to Remote Code Execution (RCE) on the server. This issue has been patched in versions 6.8.156, 25.0.90, and 26.0.12.
A vulnerability allowing remote code execution through insecure deserialization has been identified in Group-Office, an enterprise CRM and groupware tool. This issue affects versions prior to 6.8.156, 25.0.90, and 26.0.11. The vulnerability arises in the AbstractSettingsCollection model, where the _loadData() method blindly unserializes data without proper validation. An authenticated attacker can inject a serialized FileCookieJar object into a setting string, exploiting this deserialization flaw to perform arbitrary file writes, ultimately leading to remote code execution on the server.
Users can upgrade to Group-Office versions 6.8.156, 25.0.90, or 26.0.12 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| intermesh group-office | < 6.8.156 >= 25.0.1, < 25.0.90 >= 26.0.1, < 26.0.12 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | New CVE Received | [email protected] |