Junglewise Threat Intelligence

CVE-2026-34838: Intermesh Group-Office insecure deserialization in AbstractSettingsCollection

CVE-2026-34838 · Severity: critical · CVSS 9.9 · Published 2026-04-02

Executive brief

Group-Office, an enterprise customer relationship management (CRM) and groupware platform, contains a vulnerability that allows authenticated users to execute malicious code on the server. By manipulating system settings, a user with low-level access can force the application to write a malicious file to the server's filesystem. This can lead to a total takeover of the server, resulting in the theft of sensitive customer data, service disruption, and full control over the application environment.

Technical details

An insecure deserialization vulnerability exists in the `_loadData()` method of the `AbstractSettingsCollection` model in Group-Office. The application identifies serialized data by a 'serialized:' prefix and passes the subsequent string to PHP's `unserialize()` function without class validation. An authenticated attacker can exploit this by using the `core/saveSetting` controller to inject a malicious payload into the `go_settings` database table. By utilizing a POP chain involving the bundled `GuzzleHttp\Cookie\FileCookieJar` class, an attacker can trigger an arbitrary file write during object destruction. This allows for the creation of a PHP web shell, leading to Remote Code Execution (RCE). The issue is patched in versions 6.8.156, 25.0.90, and 26.0.12.

Affected products

  • Intermesh Group-Office < 6.8.156, 25.0.1 - 25.0.89, 26.0.1 - 26.0.11

Timeline

  • 2026-03-06: patched: Release of patched versions 6.8.156, 25.0.90, and 26.0.12
  • 2026-03-31: advisory: Vendor security advisory published via GitHub
  • 2026-04-02: disclosed: CVE-2026-34838 published to NVD

References

Related threats