PT-2026-26962 · Sogo · Sogo

Qhivert

·

Published

2026-03-22

·

Updated

2026-03-22

·

CVE-2026-33550

CVSS v3.1

2.6

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SOGo versions prior to 5.12.5
Description SOGo does not properly renew One-Time Passwords (OTPs) when a user disables and re-enables them. Additionally, the generated OTPs have a length of only 12 digits, which is shorter than the recommended 20 digits.
Recommendations Update to version 5.12.5 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-33550

Affected Products

Sogo