CVE-2026-46445: SQL Injection
Last updated 6 July 2026
Other sources
SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sogoto a version that resolves this vulnerability.Fixed in 5.8.0-2+deb12u3Fixed in 5.12.1-3+deb13u2Fixed in 5.12.9-1 - Upgrade
Upgrade
SOGoto a version that resolves this vulnerability.Fixed in 5.12.7 - Compensating control
If using SOGo with PostgreSQL and cannot upgrade immediately, mitigate SQL injection exposure via compensating controls (e.g., restrict network access to the SOGo service and database, and apply compensating web/application access controls) until SOGo is upgraded to 5.12.7 or later.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46445?
CVE-2026-46445 is classified as a critical vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-46445?
To fix CVE-2026-46445, upgrade SOGo to version 5.12.7 or later.
What software versions are affected by CVE-2026-46445?
Versions of Inverse SOGo prior to 5.12.7 are affected by CVE-2026-46445.
What types of attacks can CVE-2026-46445 facilitate?
CVE-2026-46445 can facilitate SQL injection attacks that compromise database security and data integrity.
Is CVE-2026-46445 specific to a database system?
Yes, CVE-2026-46445 specifically affects SOGo when used with PostgreSQL as the database.