← Vulnerability feed

Vulnerability record · CVE-2026-25511 · published 4 February 2026

CVE-2026-25511: Group-office group office server-side request forgery (ssrf) vulnerability

Group Office · Group Office

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, an authenticated user within the System Administrator group can trigger a full SSRF via the WOPI service discovery URL, including access to internal hosts/ports. The SSRF response body can be exfiltrated via the built‑in debug system, turning it into a visible SSRF. This also allows full server-side file read. This issue has been patched in versions 6.8.150, 25.0.82, and 26.0.5.

8.2 CVSS 4.0 High EPSS 0.43% · top 65.3% CWE-918 · Server-side request forgery (SSRF)
8.2CVSS 4.0 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, an authenticated user within the System Administrator group can trigger a full SSRF via the WOPI service discovery URL, including access to internal hosts/ports. The SSRF response body can be exfiltrated via the built‑in debug system, turning it into a visible SSRF. This also allows full server-side file read. This issue has been patched in versions 6.8.150, 25.0.82, and 26.0.5.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-25511 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-25512Group-office group office os command injection vulnerabilityGroup-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, there is a remote …EPSS 3.5%9.4CVE-2026-25134Group-office group office argument injection vulnerabilityGroup-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController e…EPSS 0.85%8.8CVE-2025-63406Group-office group office command injection vulnerabilityAn issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and…EPSS 0.74%8.8CVE-2023-46730Group-office group office server-side request forgery (ssrf) vulnerabilityGroup-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api…EPSS 0.60%6.9CVE-2025-25191Group-office group office cross-site scripting vulnerabilityGroup-Office is an enterprise CRM and groupware tool. This Stored XSS vulnerability exists where user input in the Name field is not properly sanitiz…EPSS 0.28%6.1CVE-2023-25292Group-office group office cross-site scripting vulnerabilityReflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive i…EPSS 0.59%6.1CVE-2020-35419Group-office group office cross-site scripting vulnerabilityCross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.EPSS 0.67%5.4CVE-2024-23941Group-office group office cross-site scripting vulnerabilityCross-site scripting vulnerability exists in Group Office prior to v6.6.182, prior to v6.7.64 and prior to v6.8.31, which may allow a remote authenti…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2026-25511), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.