PT-2026-103127 · Nginx+1 · Nginx+1

·

CVE-2026-74864

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions sogo yhn versions prior to 5.8.0~ynh9
Description The software is configured with a parameter that allows requests containing the x-webobjects-remote-user HTTP header to be treated as coming from a verified user without password validation. Because Nginx does not strip this header, an attacker can provide it arbitrarily to gain unauthorized access to any account, including those with privileged permissions.
Recommendations Update to version 5.8.0~ynh9.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74864

Affected Products

Nginx
Sogo Yhn