/Vulnerability Library

Group-Office < 26.0.5 - Remote Code Execution

CVE-2026-25512
Verified

Description

Group-Office before versions 6.8.150, 25.0.82, and 26.0.5 is vulnerable to remote code execution via OS command injection. The endpoint email/message/tnefAttachmentFromTempFile directly concatenates the user-controlled parameter tmp_file into an exec() call. By injecting shell metacharacters into tmp_file, an authenticated attacker can execute arbitrary system commands on the server.

Severity

Critical

CVSS Score

9.9

Exploit Probability

4%

Affected Product

group-office

Published Date

February 5, 2026

Template Author

omarkurt

CVE-2026-25512.yaml
9.9Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-25512
CWE ID:
cwe-78

References

https://github.com/Intermesh/groupoffice/security/advisories/GHSA-579w-jvg7-frr4https://github.com/Intermesh/groupoffice/commit/6c612deca97a6cd2a1bd4feea0ce7e8e9d907792https://nvd.nist.gov/vuln/detail/CVE-2026-25512https://vulnerabletarget.com/VT-2026-25512

Remediation Steps

Update Group-Office to version 6.8.150, 25.0.82, or 26.0.5 or later. The fix applies escapeshellarg() to properly escape file paths before passing them to exec().