CVE-2026-33550: Low severity SOGo SOGo vulnerability
Last updated 6 July 2026
Other sources
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sogoto a version that resolves this vulnerability.Fixed in 5.8.0-2+deb12u3Fixed in 5.12.1-3+deb13u2Fixed in 5.12.9-1 - Upgrade
Upgrade
SOGoto a version that resolves this vulnerability.Fixed in 5.12.5 - Configuration
Configure SOGo OTP to use a length of 20 digits (the material notes it is only 12 digits in affected versions and 20 digits is recommended).
SOGo OTP OTP length = 20 recommended
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33550?
CVE-2026-33550 is considered a moderate severity vulnerability due to its impact on user security with OTP management.
How do I fix CVE-2026-33550?
To fix CVE-2026-33550, update SOGo to version 5.12.5 or later.
What does CVE-2026-33550 impact?
CVE-2026-33550 impacts SOGo versions before 5.12.5 by not renewing the OTP under certain conditions and using a shorter OTP length.
Can disabling/enabling OTP in SOGo lead to security issues as per CVE-2026-33550?
Yes, CVE-2026-33550 highlights that toggling OTP does not renew it, which may expose users to security risks.
Is the OTP length in SOGo sufficient according to CVE-2026-33550?
No, CVE-2026-33550 indicates that SOGo uses an OTP length of only 12 digits, which is below the recommended length of 20 digits.