CVE-2026-25511 | Intermesh GroupOffice up to 6.8.149/25.0.81/26.0.4 WOPI Service server-side request forgery (GHSA-r9v4-jm2r-r9pm)
A vulnerability was found in Intermesh GroupOffice up to 6.8.149/25.0.81/26.0.4. It has been declared as critical. Affected is an unknown function of the component WOPI Service. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-25511. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.