CVE-2026-33550
Received
Received - Intake
Insecure OTP Handling in SOGo Before 5.12.5 Causes Authentication Risk
Publication date: 2026-03-22
Last updated on: 2026-03-23
Assigner: MITRE
Description
Description
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| alinto | sogo | to 5.12.5 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-308 | The product uses an authentication algorithm that uses a single factor (e.g., a password) in a security context that should require more than one factor. |