critical · CVSS v3 8.3 · CVSS v4 8.7
CVE-2026-93453
SOGo versions before 5.12.11 can construct password-reset links using a client-supplied Origin header as the link authority. This can cause
Overview
SOGo versions before 5.12.11 can construct password-reset links using a client-supplied Origin header as the link authority. This can cause valid recovery tokens to be delivered in links pointing to attacker-controlled domains. It matters because it can enable account takeover for users who rely on SOGo password recovery.
Description
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.
Impact
Confidentiality and integrity are affected because valid password-reset tokens may be exposed in links to untrusted domains. Availability is less directly affected, but account compromise can disrupt access to mail, calendar, and contacts. Users of SOGo webmail/groupware and administrators responsible for account recovery are impacted. The risk is elevated where recovery emails are sent to external or shared addresses.
Remediation
Upgrade SOGo to 5.12.11 or later. Until patched, restrict password-reset link generation to trusted server-controlled hostnames and validate or ignore untrusted Origin or Referer values. Monitor outbound recovery emails and webmail logs for suspicious reset-link destinations, unexpected Origin values, and repeated failed or successful password resets.
Affected products
- SOGo < 5.12.11
Scores
- Severity
- critical
- CVSS v2
- 9.7
- CVSS v3
- 8.3
- CVSS v4
- 8.7
- EPSS
- —