🔐 CVE Alert

CVE-2026-74865

UNKNOWN 0.0

Authentication Bypass in sogo_yhn

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.

CWE CWE-639
Vendor yunohost-apps
Product sogo_yhn
Published Sep 30, 2026
Last Updated Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for yunohost-apps sogo_yhn

Be the first to know when new unknown vulnerabilities affecting yunohost-apps sogo_yhn are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

YunoHost-Apps / sogo_yhn
0 < 5.8.0~ynh9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/09/CVE-2026-74864 forum.yunohost.org: https://forum.yunohost.org/t/sogo-critical-vulnerability-fixed-in-5-8-0-ynh9/42699

Credits

Przemysław Knycz WeKrwi.IT https://github.com/djrzulf