CVE-2026-3054: Alinto SOGo cross site scripting
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sogoto a version that resolves this vulnerability.Fixed in 5.12.1-3+deb13u2Fixed in 5.12.9-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3054?
CVE-2026-3054 has been classified as a high severity vulnerability due to its potential for exploitation through cross site scripting.
How do I fix CVE-2026-3054?
To fix CVE-2026-3054, upgrade Alinto SOGo to a version that is beyond 5.12.4 as per the vendor's recommendations.
What software versions are affected by CVE-2026-3054?
CVE-2026-3054 affects Alinto SOGo versions 5.12.3 and 5.12.4.
Can CVE-2026-3054 be exploited remotely?
Yes, CVE-2026-3054 can be exploited remotely by manipulating the argument hint leading to cross site scripting.
Is there a known exploit for CVE-2026-3054?
Yes, the exploit for CVE-2026-3054 is publicly available and might be used by attackers.