
Authenticated remote code execution exploit for Group-Office via TNEF attachment handler, targeting CVE-2026-25512 with OS command injection.
Author: Mohammed Idrees Banyamer
Handle: @banyamer_security
GitHub: mbanyamer
Date: February 04, 2026
Group-Office (Intermesh) < 26.0.4 – Authenticated RCE via TNEF Attachment Handler
CVE-2026-25512
CWE-78 (OS Command Injection)
< 26.0.4 (also affects some 25.x / 6.8.x branches)
26.0.5 / 25.0.82 / 6.8.150
High (CVSS 8.8 – AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Group-Office versions prior to 26.0.4 are vulnerable to authenticated OS command injection in the endpoint: