CVE-2026-25512Disclosure(group-office / group_office)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (RCE) vulnerability in Group-Office. The endpoint email/message/tnefAttachmentFromTempFile directly concatenates the user-controlled parameter tmp_file into an exec() call. By injecting shell metacharacters into tmp_file, an authenticated attacker can execute arbitrary system commands on the server. This issue has been patched in versions 6.8.150, 25.0.82, and 26.0.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • group_office

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
group_office

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-04: 2Mentions · 2026-02-05: 1Mentions · 2026-03-02: 1Technical Details · 2026-02-04: 2Technical Details · 2026-02-05: 1Technical Details · 2026-03-02: 102-0402-0503-02
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure2
2026-02-051
Disclosure1
2026-03-021
Disclosure1
Full discourse4 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-25512 - critical 🚨 Group-Office < 26.0.5 - Remote Code Execution > Group-Office before versions 6.8.150, 25.0.82, and 26.0.5 is vulnerable to remote cod... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-25512 @pdnuclei #NucleiTemplates #cve

    Post summary

    A critical remote code execution vulnerability (CVE‑2026‑25512) in Group‑Office versions prior to 26.0.5 has been disclosed, with specific affected versions identified.

    00023237
    894 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: CVE-2026-25512 OS command injection, affecting #GroupOffice allows authenticated attackers to inject shellcode in a user-controlled parameter to execute system commands on the server. #RCE #Patch #Patch #Patch

    Post summary

    A warning about CVE-2026-25512, an OS command injection in GroupOffice allowing authenticated attackers to execute arbitrary system commands, but no PoC, exploit code, patch details, or evidence of active exploitation are provided.

    01000218
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25512 Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (R… https://www.cve.org/CVERecord?id=CVE-2026-25512

    Post summary

    The post reports a remote code execution vulnerability (CVE‑2026‑25512) in older Group‑Office versions, with no evidence of PoC, exploit code, active attacks, or patches.

    00010174
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25512: Group-Office is vulnerable to RC... Classic exec() command injection in Group-Office's TNEF handler lets authenticated users pwn servers via malicious emai... https://zerodaysignal.com/vulnerability/CVE-2026-25512 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑25512, a classic exec() command injection flaw in Group‑Office’s TNEF handler that permits authenticated users to execute arbitrary commands. No PoC, exploit code, or patch information is provided.

    0000070
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgroup-officegroup_office---

Explore more