CVE-2026-25512

Severity CVSS v4.0:
CRITICAL
Type:
CWE-78 OS Command Injections
Publication date:
04/02/2026
Last modified:
11/02/2026

Description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (RCE) vulnerability in Group-Office. The endpoint email/message/tnefAttachmentFromTempFile directly concatenates the user-controlled parameter tmp_file into an exec() call. By injecting shell metacharacters into tmp_file, an authenticated attacker can execute arbitrary system commands on the server. This issue has been patched in versions 6.8.150, 25.0.82, and 26.0.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* 6.8.150 (excluding)
cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* 25.0.1 (including) 25.0.82 (excluding)
cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:* 26.0.1 (including) 26.0.5 (excluding)