Group-Office < 26.0.5 - Remote Code Execution
CVE-2026-25512
Verified
Description
Group-Office before versions 6.8.150, 25.0.82, and 26.0.5 is vulnerable to remote code execution via OS command injection. The endpoint email/message/tnefAttachmentFromTempFile directly concatenates the user-controlled parameter tmp_file into an exec() call. By injecting shell metacharacters into tmp_file, an authenticated attacker can execute arbitrary system commands on the server.
Severity
Critical
CVSS Score
9.9
Exploit Probability
4%
Affected Product
group-office
Published Date
February 5, 2026
Template Author
omarkurt
CVE-2026-25512.yaml
9.9Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-25512
CWE ID:
cwe-78
Remediation Steps
Update Group-Office to version 6.8.150, 25.0.82, or 26.0.5 or later. The fix applies escapeshellarg() to properly escape file paths before passing them to exec().