Executive brief
SOGo, an open-source collaborative software server, is vulnerable to a security flaw in its password management system. When configured to use PostgreSQL or MariaDB with cleartext passwords, an attacker could manipulate database queries to gain unauthorized access to data or disrupt operations. Organizations using these specific database configurations should update to version 5.12.7 immediately to protect their user credentials and system integrity.
Technical details
An SQL injection vulnerability exists in SOGo's 'changePasswordForLogin' function within the SQLSource component. The root cause is the improper neutralization of special elements (CWE-89) when handling the 'c_password' field, specifically where the code used string formatting instead of proper SQL adaptors for parameterization. This vulnerability is exploitable when SOGo is configured with a PostgreSQL or MariaDB user source and 'userPasswordAlgorithm' is set to 'none', 'plain', or 'cleartext'. An authenticated attacker with low privileges could potentially execute arbitrary SQL commands to read, modify, or delete database content. The issue is resolved in version 5.12.7 by implementing proper SQL adaptors for user source queries.
Affected products
- Alinto SOGo < 5.12.7
Timeline
- 2026-03-24: patched: Fix committed to upstream repository
- 2026-03-30: advisory: SOGo v5.12.7 released with security warning
- 2026-05-14: disclosed: CVE-2026-46446 published