CVE-2026-74864
Received Received - Intake

SOGo Authentication Bypass via X-WebObjects-Remote-User Header

Vulnerability report for CVE-2026-74864, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CERT.PL

Description

sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password. This issue was fixed in version 5.8.0~ynh9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
sogo sogo 5.8.0~ynh9
yunohost apps to 5.8.0~ynh9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in sogo_yhn software affecting SOGo. It allows attackers to gain unauthorized access to any user account, including privileged ones, by manipulating the HTTP header 'x-webobjects-remote-user'. The software incorrectly treats requests with this header as authenticated without verifying passwords, and Nginx does not strip this header, enabling exploitation.

Detection Guidance

Check SOGo version with command: dpkg -l | grep sogo. If version is below 5.8.0~ynh9, the system is vulnerable. Inspect Nginx configuration for presence of x-webobjects-remote-user header handling. Monitor logs for unusual authentication attempts or access patterns.

Impact Analysis

An attacker could impersonate any user, access sensitive data, perform unauthorized actions, or escalate privileges. This includes reading emails, modifying settings, or gaining administrative control over the SOGo instance. The impact is severe due to the lack of password validation.

Compliance Impact

This vulnerability likely violates compliance requirements such as GDPR (data protection) and HIPAA (health information security) by allowing unauthorized access to sensitive data. It undermines authentication controls, potentially leading to data breaches and non-compliance with regulatory standards.

Mitigation Strategies

Upgrade SOGo to version 5.8.0~ynh9 or higher immediately. Ensure YunoHost is updated to 12.1.38 or higher before upgrading SOGo. Restart the server after applying updates. Temporarily disable SSO if upgrading is not feasible until full SOGo 6 transition.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74864. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart