CVE-2026-25511
EUVD-2026-534804.02.2026, 21:16
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, and 26.0.5, an authenticated user within the System Administrator group can trigger a full SSRF via the WOPI service discovery URL, including access to internal hosts/ports. The SSRF response body can be exfiltrated via the built‑in debug system, turning it into a visible SSRF. This also allows full server-side file read. This issue has been patched in versions 6.8.150, 25.0.82, and 26.0.5.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| group-office | group_office | 6.8.0 ≤ 𝑥 < 6.8.150 |
| group-office | group_office | 25.0.1 ≤ 𝑥 < 25.0.82 |
| group-office | group_office | 26.0.1 ≤ 𝑥 < 26.0.5 |
𝑥
= Vulnerable software versions