CVE-2026-25134: Group-Office Group Office
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip file to achieve remote code execution. This vulnerability is fixed in 6.8.150, 25.0.82, and 26.0.5.
Affected products
- Group-Office Group Office: before 6.8.150 (fixed in 6.8.150); from 25.0.1, before 25.0.82 (fixed in 25.0.82); from 26.0.1, before 26.0.5 (fixed in 26.0.5)
Published 2026-02-02. Last modified 2026-06-17.