CVE-2026-25134 is a critical remote code execution (RCE) vulnerability affecting Group-Office versions prior to 6.8.150, 25.0.82, and 26.0.5. The vulnerability stems from the MaintenanceController's zipLanguage action, which insecurely passes user-supplied input to a system zip command via exec(). This flaw carries a high CVSS score of 8.8, indicating a severe risk. An authenticated attacker can exploit this by uploading a specially crafted zip file, leading to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog, suggesting it is not under active exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.8.150CPE matchmatch criteria | cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* | ||
>= 25.0.1, < 25.0.82CPE matchmatch criteria | cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* | ||
>= 26.0.1, < 26.0.5CPE matchmatch criteria | cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.