logo

CVE-2026-34838 (CVSS 10): Critical RCE Flaw Uncovered in GroupOffice CRM

ID: cfec1c10-1146-5876-89dd-5c51c6bc6e65

STIX ID: report--cfec1c10-1146-5876-89dd-5c51c6bc6e65

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Critical RCE vulnerability (CVE-2026-34838) in GroupOffice (<=26.0.11) arises from unsafe use of PHP unserialize on saved settings; an authenticated low-privileged user can inject serialized objects and, via a Guzzle POP chain and FileCookieJar, achieve arbitrary file write and deploy a web shell. Patches are available and administrators should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.