CVE-2026-74865
Authentication Bypass in sogo_yhn
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.
| CWE | CWE-639 |
| Vendor | yunohost-apps |
| Product | sogo_yhn |
| Published | Sep 30, 2026 |
| Last Updated | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for yunohost-apps sogo_yhn
Be the first to know when new unknown vulnerabilities affecting yunohost-apps sogo_yhn are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
YunoHost-Apps / sogo_yhn
0 < 5.8.0~ynh9
References
Credits
Przemysław Knycz WeKrwi.IT https://github.com/djrzulf