PT-2026-41735 · Sogo · Sogo

Dninh

·

Published

2026-05-18

·

Updated

2026-05-19

·

CVE-2026-8851

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SOGo version 5.12.7
Description An issue in the Access Control List management functionality allows authenticated users to extract arbitrary data from the database. This is achieved by injecting SQL subqueries through the uid parameter of the "/addUserInAcls" endpoint. Attackers can use malicious SQL code to write extracted data into the sogo acl table and subsequently retrieve it via the "/acls" API, creating an out-of-band data exfiltration channel.
Recommendations As a temporary workaround, restrict access to the "/addUserInAcls" endpoint or avoid using the uid parameter until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-8851

Affected Products

Sogo