Description
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password.




This issue was fixed in version 5.8.0~ynh9.
Published: 2026-09-30
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Patch Immediately
AI Analysis

Impact

A flaw in sogo_yhn’s SOGo configuration causes any HTTP request that includes the x-webobjects-remote-user header to be treated as originating from the specified user, bypassing password checks. The flaw lets an attacker pass arbitrary values for this header and gain access as any account, including privileged ones, without authentication.

Affected Systems

The vulnerability affects YunoHost‑Apps sogo_yhn installations that have not applied the fix introduced in version 5.8.0~ynh9. Any instance running a prior version is vulnerable.

Risk and Exploitability

With a CVSS score of 9.3 the issue is considered critical. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog; nonetheless the lack of authentication required for the bypass makes it trivially exploitable over the network. Attackers can trigger the capitalized bypass by simply including the x-webobjects-remote-user header in an HTTP request and are able to assume any user’s identity, including administrator-level access.

Generated by OpenCVE AI on September 30, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade sogo_yhn to 5.8.0~ynh9 or later
  • Configure Nginx to reject or strip the x-webobjects-remote-user header for all inbound requests
  • Ensure the SOGo configuration option that enables the header for authentication is disabled or removed

Generated by OpenCVE AI on September 30, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password. This issue was fixed in version 5.8.0~ynh9.
Title Authentication Bypass in sogo_yhn
Weaknesses CWE-639
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-30T12:50:52.363Z

Reserved: 2026-08-17T10:19:51.723Z

Link: CVE-2026-74864

cve-icon Vulnrichment

Updated: 2026-09-30T12:50:49.501Z

cve-icon NVD

Status : Received

Published: 2026-09-30T13:17:19.913

Modified: 2026-09-30T13:17:19.913

Link: CVE-2026-74864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key