๐Ÿ” CVE Alert

CVE-2026-93453

HIGH 8.3

SOGo before 5.12.11 Password Reset Token Interception via Origin Header

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.

CWE CWE-640
Vendor alinto
Product sogo
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for alinto sogo

Be the first to know when new high vulnerabilities affecting alinto sogo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

Alinto / SOGo
0 < 5.12.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sogo.nu: https://www.sogo.nu/news/2026/sogo-v51211-released.html github.com: https://github.com/Alinto/sogo/commit/382118a93b6925de2ce7f774abc1865ebea2dbba github.com: https://github.com/Alinto/sogo/commit/04a3e9823889acaf6c247b224f5f7a0108f8f829 github.com: https://github.com/Alinto/sogo/blob/SOGo-5.12.10/UI/MainUI/SOGoRootPage.m#L1375 github.com: https://github.com/Alinto/sogo vulncheck.com: https://www.vulncheck.com/advisories/sogo-before-5.12.11-password-reset-token-interception-via-origin-header

Credits

Faceless0x7