CVE-2026-74865
Received Received - Intake

SOGo Trust Proxy Authentication Bypass

Vulnerability report for CVE-2026-74865, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: CERT.PL

Description

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sogo sogo 5.8.0~ynh9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in sogo_yhn software versions prior to 5.8.0~ynh9. It involves a configuration setting 'SOGoTrustProxyAuthentication=YES' which causes SOGo to bypass password checks during HTTP Basic authentication. An attacker can exploit this by providing a valid username and any arbitrary password to gain unauthorized access to that user's account without proper authentication.

Detection Guidance

Check SOGo configuration files for the parameter SOGoTrustProxyAuthentication=YES. Inspect HTTP Basic authentication logs for successful logins with arbitrary passwords. Use network monitoring tools to detect unusual header manipulation attempts like x-webobjects-remote-user.

Impact Analysis

An unauthenticated attacker could gain access to any user account including privileged accounts by supplying a valid username and any password. This could lead to unauthorized data access, modification, or exfiltration depending on the user's permissions. The impact includes potential loss of confidentiality, integrity, and availability of sensitive information stored in SOGo.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face compliance violations, regulatory fines, and reputational damage if this vulnerability is exploited to access sensitive data.

Mitigation Strategies

Upgrade SOGo to version 5.8.0~ynh9 or later immediately. Disable HTTP Basic authentication if not required. Review and remove any custom configurations enabling SOGoTrustProxyAuthentication. Restrict network access to SOGo services until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-74865. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart