CVE-2026-33755 Details
Description
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `Contact/query` endpoint allows any authenticated user with basic addressbook access to extract arbitrary data from the database — including active session tokens of other users. This enables full account takeover of any user, including the System Administrator, without knowing their password. Versions 6.8.158, 25.0.92, and 26.0.17 fix the issue.
A SQL injection vulnerability has been identified in Group-Office versions prior to 6.8.158, 25.0.92, and 26.0.17. This vulnerability exists in the JMAP 'Contact/query' endpoint, specifically within the 'addressBookIds' filter. It allows authenticated users with basic address book access to inject malicious SQL, extracting arbitrary data from the database. This includes active session tokens of other users, enabling full account takeover, even of the System Administrator, without requiring their password.
Users can upgrade to Group-Office versions 6.8.158, 25.0.92, or 26.0.17 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Intermesh/groupoffice/security/advisories/GHSA-3gc4-5993-c2qc | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| intermesh group-office | < 6.8.158 >= 25.0.1, < 25.0.92 >= 26.0.1, < 26.0.17 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |