CVE-2026-74865: Authentication Bypass in sogo_yhn
sogoyhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.
This issue was fixed in version 5.8.0~ynh9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sogo_yhnto a version that resolves this vulnerability.Fixed in 5.8.0~ynh9
Event History
Frequently Asked Questions
Which deployments are affected?
YunoHost sogo_yhn deployments that use the vulnerable configuration with SOGoTrustProxyAuthentication set to YES are affected. The issue is fixed in version 5.8.0~ynh9.
What does an attacker need to exploit this issue?
An attacker needs only the username of an existing user. They can authenticate through HTTP Basic authentication using that username and an arbitrary password.
What is the impact of successful exploitation?
The attacker can log in to the targeted existing user's SOGo account without knowing that user's password.