Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-25512-PoC-Group-Office-Authenticated-RCE — Authenticated remote code execution exploit for Group-Office via TNEF attachment handler, targeting CVE-2026-25512 with OS command injection. | Kitploit
Tools/GitHubGitHub/mbanyamer/cve-2026-25512-poc-group-office-authenticated-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubmbanyamer/cve-2026-25512-poc-group-office-authenticated-rce

CVE-2026-25512-PoC-Group-Office-Authenticated-RCE

Authenticated remote code execution exploit for Group-Office via TNEF attachment handler, targeting CVE-2026-25512 with OS command injection.

View Repository
6 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-25512 PoC – Group-Office Authenticated RCE via TNEF Handler

Author: Mohammed Idrees Banyamer
Handle: @banyamer_security
GitHub: mbanyamer
Date: February 04, 2026

Exploit Title

Group-Office (Intermesh) < 26.0.4 – Authenticated RCE via TNEF Attachment Handler

CVE

CVE-2026-25512

CWE

CWE-78 (OS Command Injection)

Vendor

Intermesh / Group-Office

Vulnerable Versions

< 26.0.4 (also affects some 25.x / 6.8.x branches)

Fixed Versions

26.0.5 / 25.0.82 / 6.8.150

Patch Commit

6c612deca97a6cd2a1bd4feea0ce7e8e9d907792

GHSA

GHSA-579w-jvg7-frr4

Severity

High (CVSS 8.8 – AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Description

Group-Office versions prior to 26.0.4 are vulnerable to authenticated OS command injection in the endpoint:

Download Tool