CVE-2026-93453: SOGo before 5.12.11 Password Reset Token Interception via Origin Header
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SOGoto a version that resolves this vulnerability.Fixed in 5.12.11
Event History
Frequently Asked Questions
Which SOGo versions are affected?
SOGo versions before 5.12.11 are affected. Version 5.12.11 is the first version identified in the provided data as not affected.
Does exploitation require an attacker account or prior access?
No. An unauthenticated attacker can submit password-recovery requests using a malicious Origin header.
What user action is needed for account takeover?
The victim receives a password-reset email containing a link that points to attacker-controlled infrastructure. Following that link can expose the valid reset token to the attacker and enable account takeover.