Description
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via intercepted password‑reset tokens
Action: Immediate Patch
AI Analysis

Impact

SOGo versions preceding 5.12.11 construct password‑reset URLs that use the client‑supplied Origin header as the authority. An unauthenticated attacker can supply a malicious Origin header when initiating a password reset request, causing the system to embed the password‑reset token in an email that points to the attacker’s domain. The attacker then obtains the token and can perform an account takeover. This flaw is an instance of credential reuse through weak origin handling (CWE‑640).

Affected Systems

All versions of Alinto SOGo released before 5.12.11 are affected. The vulnerability is present in any deployment that uses the legacy password‑reset flow without patching to 5.12.11 or newer. No specific patch release details beyond the mitigation path are listed in the advisory.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity flaw. The EPSS score of less than 1% shows that current exploitation activity is very low, and the vulnerability is not yet listed in CISA’s KEV catalog. It is an unauthenticated, remote flaw that can be exploited via a crafted HTTP request where the attacker controls the Origin header. The likely attack vector is a client‑side request that triggers a password reset email, which is then intercepted or redirected by the attacker. The consequences are full account takeover for the targeted user. The risk is elevated for environments that allow arbitrary Origin headers in the password reset path and do not enforce domain validation.

Generated by OpenCVE AI on September 19, 2026 at 08:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to SOGo 5.12.11 or later to remove the use of the Origin header in password‑reset URLs.
  • Configure SOGo to ignore or validate the Origin header for password‑reset links, limiting link generation to trusted domains if an upgrade is unavailable.
  • Monitor password‑reset requests for unexpected Origin headers or reset emails pointing to unapproved domains and investigate or block such activity.

Generated by OpenCVE AI on September 19, 2026 at 08:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.
Title SOGo before 5.12.11 Password Reset Token Interception via Origin Header
First Time appeared Alinto
Alinto sogo
Weaknesses CWE-640
CPEs cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*
Vendors & Products Alinto
Alinto sogo
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T18:02:43.378Z

Reserved: 2026-09-17T22:45:31.286Z

Link: CVE-2026-93453

cve-icon Vulnrichment

Updated: 2026-09-18T18:02:38.786Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T00:17:49.693

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-93453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:30:16Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password