File Upload Vulnerability in Open-Xchange App Suite
CVE-2025-59026

5.4MEDIUM

Key Information:

Vendor
CVE Published:
27 November 2025

What is CVE-2025-59026?

A vulnerability within the Open-Xchange App Suite enables attackers to upload malicious files. When users follow links controlled by the attacker, these files can execute script code within the context of the user's account. This can lead to unintended actions, such as the exfiltration of sensitive information. Users are urged to apply the recommended updates and security patches to mitigate this risk.

Affected Version(s)

OX App Suite 0 <= 8.35.110

OX App Suite 0 <= 8.39.85

OX App Suite 0 <= 8.40.73

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.