CVE-2026-74864: Authentication Bypass in sogo_yhn
sogoyhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password.
This issue was fixed in version 5.8.0~ynh9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sogo_yhnto a version that resolves this vulnerability.Fixed in 5.8.0~ynh9
Event History
Frequently Asked Questions
Which deployments are exposed?
YunoHost sogo_yhn deployments that use the affected configuration are exposed because Nginx does not remove the x-webobjects-remote-user header supplied by clients. Any client able to send requests to the SOGo service can provide this header.
What does an attacker need to exploit the issue?
The attacker only needs to send a request containing an x-webobjects-remote-user header identifying the account they want to impersonate. No password validation is performed, and the target can be a privileged user.
What version fixes the issue?
The issue was fixed in sogo_yhn version 5.8.0~ynh9.