CVE-2026-33755
8.8Intermesh · Group-Office
An authenticated SQL injection vulnerability in the Group-Office Contact/query endpoint allows authenticated users to extract database data and perform full account takeovers.
Executive summary
A critical SQL injection flaw in Group-Office allows authenticated attackers to perform full account takeovers, including the compromise of System Administrator accounts.
Vulnerability
This is an SQL injection vulnerability (CWE-89) located in the JMAP Contact/query endpoint. The flaw allows any authenticated user with basic addressbook access to execute arbitrary database queries, leading to the exfiltration of session tokens and subsequent full account takeover.
Business impact
The ability for an authenticated user to extract database contents and hijack privileged accounts represents a severe security risk. Given the CVSS score of 8.8, this vulnerability is classified as High severity because it grants an attacker full control over the application environment and sensitive customer data. Successful exploitation could lead to unauthorized access to enterprise communications, loss of confidential business information, and complete system compromise.
Remediation
Immediate Action: Update Group-Office to version 6.8.158, 25.0.92, 26.0.17, or later to apply the necessary security patches.
Proactive Monitoring: Review web access logs for anomalous requests to the JMAP Contact/query endpoint and monitor database query logs for unusual syntax or unexpected data volume exports.
Compensating Controls: Implement Web Application Firewall (WAF) rules designed to detect and block common SQL injection patterns targeting JMAP API endpoints.
Exploitation status
Public Exploit Available: Unknown (No confirmed public exploit exists in the provided data).
Analyst recommendation
Organizations utilizing Group-Office should prioritize this update immediately. Because the vulnerability facilitates full account takeover by extracting session tokens, it poses a significant threat to internal security posture and data integrity. Apply the provided version updates as soon as possible to mitigate the risk of unauthorized database access and privilege escalation.