# CVE-2026-25134

## Summary

- **CVE ID:** CVE-2026-25134
- **Severity:** CRITICAL
- **CVSS Score:** 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-88
- **Published:** Feb 2, 2026
- **Last Modified:** Mar 12, 2026

## Description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip file to achieve remote code execution. This vulnerability is fixed in 6.8.150, 25.0.82, and 26.0.5.

## Affected Products

- Intermesh — groupoffice (< 6.8.150)
- Intermesh — groupoffice (>= 25.0.0, < 25.0.82)
- Intermesh — groupoffice (>= 26.0.0, < 26.0.5)

## References

- [CNA](https://github.com/Intermesh/groupoffice/security/advisories/GHSA-v39j-549w-8849)
- [CNA](https://github.com/Intermesh/groupoffice/commit/d28490a6a29936db7888aa841ab8ade88800540b)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.83%
- **EPSS Percentile:** 55.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._