Nginx · Nginx · CVE-2026-74864
**Name of the Vulnerable Software and Affected Versions**
sogo yhn versions prior to 5.8.0~ynh9
**Description**
The software is configured with a parameter that allows requests containing the `x-webobjects-remote-user` HTTP header to be treated as coming from a verified user without password validation. Because Nginx does not strip this header, an attacker can provide it arbitrarily to gain unauthorized access to any account, including those with privileged permissions.
**Recommendations**
Update to version 5.8.0~ynh9.