PT-2026-40847 · Alinto · Sogo

Published

2026-05-14

·

Updated

2026-05-14

·

CVE-2026-46446

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c password = '%@' in changePasswordForLogin.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-46446

Affected Products

Sogo