Sogo · Sogo · CVE-2026-93453
**Name of the Vulnerable Software and Affected Versions**
SOGo versions prior to 5.12.11
**Description**
Unauthenticated attackers can redirect password recovery tokens to domains under their control. This occurs because the software constructs password-reset links using the client-supplied `Origin` header as the authority. By submitting recovery requests with a malicious `Origin` header, attackers can cause valid reset tokens to be sent to victims via links that point to attacker-controlled infrastructure, potentially leading to account takeover.
**Recommendations**
Update to version 5.12.11 or later.