CVE-2026-27947
Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulnerability in the TNEF attachment processing flow. The vulnerable path extracts attacker-controlled files from `winmail.dat` and then invokes `zip` with a shell wildcard (`*`). Because extracted filenames are attacker-controlled, they can be interpreted as `zip` options and lead to arbitrary command execution. Versions 26.0.9, 25.0.87, and 6.8.154 fix the issue.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.73%
- CWE
- CWE-88, CWE-434
- Published
- 2026-02-27
- Last modified
- 2026-03-12
Affected products
- Intermesh groupoffice
- Intermesh groupoffice
- Intermesh groupoffice
Weakness type
Related vulnerabilities
- CVE-2026-8044 — CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')...
- CVE-2026-87818 — GitPython 3.1.59 Local File Content Oracle via --no-index
- CVE-2026-87794 — bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination
- CVE-2026-78635 — Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument
- CVE-2026-71377 — Command Argument Injection Vulnerability in Cosminexus Component Container
- CVE-2026-84256 — An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on...
- CVE-2026-86060 — SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
- CVE-2026-85626 — git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters