


Perceptive Security
SOC/SIEM Consultancy

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injecti…
Published:
26 maart 2026 om 23:00:00
Alert date:
27 maart 2026 om 20:07:04
Source:
nvd.nist.gov
Enterprise Applications, Database & Storage
Group-Office, an enterprise CRM and groupware tool, contains an authenticated SQL injection vulnerability in the JMAP Contact/query endpoint. The vulnerability affects versions prior to 6.8.158, 25.0.92, and 26.0.17. Any authenticated user with basic addressbook access can exploit this flaw to extract arbitrary data from the database, including active session tokens of other users. This enables complete account takeover of any user, including System Administrators, without requiring password knowledge. The vulnerability has been patched in the specified versions.
Technical details
Mitigation steps:
Affected products:
Group-Office
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33755
https://github.com/Intermesh/groupoffice/security/advisories/GHSA-3gc4-5993-c2qc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
