« Volver al listado

CVE-2026-34838

Estado: AnalizadaCrítica (9.9)—

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directly to Remote Code Execution (RCE) on the server. This issue has been patched in versions 6.8.156, 25.0.90, and 26.0.12.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso remoto autenticado (PR:L, AV:N) a servicio de aplicación; deserialización insegura con inyección de objeto serializado permite ejecución de código arbitrario y escritura de archivos en servidor.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-34838",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-34838",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-03T12:55:40.674883Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "Intermesh",
          "product": "groupoffice",
          "versions": [
            {
              "status": "affected",
              "version": "< 6.8.156"
            },
            {
              "status": "affected",
              "version": "< 25.0.90"
            },
            {
              "status": "affected",
              "version": "< 26.0.12"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-02T20:16:28.150",
  "references": [
    {
      "url": "https://github.com/Intermesh/groupoffice/releases/tag/v25.0.90",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Intermesh/groupoffice/releases/tag/v26.0.12",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Intermesh/groupoffice/releases/tag/v6.8.156",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Intermesh/groupoffice/security/advisories/GHSA-h22j-frrf-5vxq",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settings are loaded. By injecting a serialized FileCookieJar object into a setting string, an authenticated attacker can achieve Arbitrary File Write, leading directly to Remote Code Execution (RCE) on the server. This issue has been patched in versions 6.8.156, 25.0.90, and 26.0.12."
    },
    {
      "lang": "es",
      "value": "Group-Office es una herramienta de gestión de relaciones con clientes empresariales y de groupware. Antes de las versiones 6.8.156, 25.0.90 y 26.0.12, una vulnerabilidad en el modelo AbstractSettingsCollection conduce a deserialización insegura cuando estas configuraciones son cargadas. Al inyectar un objeto FileCookieJar serializado en una cadena de configuración, un atacante autenticado puede lograr escritura arbitraria de archivos, lo que conduce directamente a ejecución remota de código (RCE) en el servidor. Este problema ha sido parcheado en las versiones 6.8.156, 25.0.90 y 26.0.12."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58242448-BF4C-435F-8DAA-FC1F28CD181B",
              "versionEndExcluding": "6.8.156"
            },
            {
              "criteria": "cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CA282F8-C073-4224-B3D0-5F1103FFE93F",
              "versionEndExcluding": "25.0.90",
              "versionStartIncluding": "25.0.1"
            },
            {
              "criteria": "cpe:2.3:a:intermesh:group-office:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "903696F9-950E-4D3F-8F0B-613C6C599F98",
              "versionEndExcluding": "26.0.12",
              "versionStartIncluding": "26.0.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}