This issue was fixed in version 5.8.0~ynh9.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yunohost-apps
Yunohost-apps sogo Yhn |
|
| Vendors & Products |
Yunohost-apps
Yunohost-apps sogo Yhn |
Wed, 30 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password. This issue was fixed in version 5.8.0~ynh9. | |
| Title | Authentication Bypass in sogo_yhn | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-30T12:50:52.363Z
Reserved: 2026-08-17T10:19:51.723Z
Link: CVE-2026-74864
Updated: 2026-09-30T12:50:49.501Z
Status : Deferred
Published: 2026-09-30T13:17:19.913
Modified: 2026-09-30T19:57:08.043
Link: CVE-2026-74864
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:33:45Z