PT-2026-95190 · Sogo · Sogo

·

CVE-2026-93453

·

Published

2026-09-14

·

Updated

2026-09-18

CVSS v2.0

9.7

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions SOGo versions prior to 5.12.11
Description Unauthenticated attackers can redirect password recovery tokens to domains under their control. This occurs because the software constructs password-reset links using the client-supplied Origin header as the authority. By submitting recovery requests with a malicious Origin header, attackers can cause valid reset tokens to be sent to victims via links that point to attacker-controlled infrastructure, potentially leading to account takeover.
Recommendations Update to version 5.12.11 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15032
CVE-2026-93453

Affected Products

Sogo