← Browse

CVE-2026-34838

Medium

Elevated severity or exploit probability.

CVSS base
9.9 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.0%
61.0th percentile
CISA KEV
Not listed
Weakness / dates
CWE-502
Published 2026-04-02 · modified 2026-07-24

Description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directly to Remote Code Execution (RCE) on the server. This issue has been patched in versions 6.8.156, 25.0.90, and 26.0.12.

Affected

intermesh

References

Official: NVD · CVE.org