CVE-2026-74865
9.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.
This issue was fixed in version 5.8.0~ynh9.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| YunoHost-Apps | sogo_yhn | 0 < 5.8.0~ynh9 | affected |
Weaknesses
- CWE-639: CWE-639 Authorization bypass through User-Controlled key
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://cert.pl/en/posts/2026/09/CVE-2026-74864
- https://forum.yunohost.org/t/sogo-critical-vulnerability-fixed-in-5-8-0-ynh9/42699
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.