CVE-2026-8496: A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS file, with an onrepeat event handler, is insufficiently sanitized before being rendered in the webmail interface. A remote attacker can execute JavaScript in the victim's browser when the malicious calendar invite is viewed. Successful exploitation may allow mailbox access, email and contact theft, session hijacking, and other actions allowed by an authenticated user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sogoto a version that resolves this vulnerability.Fixed in 5.8.0-2+deb12u3Fixed in 5.12.1-3+deb13u2Fixed in 5.12.9-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8496?
CVE-2026-8496 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2026-8496?
To fix CVE-2026-8496, upgrade Alinto SOGo to version 5.12.8 or later.
Who is affected by CVE-2026-8496?
CVE-2026-8496 affects users of Alinto SOGo version 5.12.7.
What kind of attack is possible with CVE-2026-8496?
CVE-2026-8496 allows attackers to execute arbitrary JavaScript within an authenticated SOGo webmail session.
Can CVE-2026-8496 be exploited remotely?
Yes, CVE-2026-8496 can be exploited remotely through malicious ICS calendar invitation files.