Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote code execution (RCE) vulnerability in Group-Office. The endpoint email/message/tnefAttachmentFromTempFile directly concatenates the user-controlled parameter tmp_file into an exec() call. By injecting shell metacharacters into tmp_file, an authenticated attacker can execute arbitrary system commands on the server. This issue has been patched in versions 6.8.150, 25.0.82, and 26.0.5.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-78"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25512.json"
}{
"cpe": "cpe:2.3:a:group-office:group_office:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "6.8.150"
},
{
"introduced": "25.0.1"
},
{
"fixed": "25.0.82"
},
{
"introduced": "26.0.1"
},
{
"fixed": "26.0.5"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}