Junglewise Threat Intelligence

CVE-2026-46446: Alinto SOGo SQL injection in changePasswordForLogin

CVE-2026-46446 · Severity: high · CVSS 7.1 · Published 2026-05-14

Technologies: Alinto Sogo. Vendors: Alinto.

Executive brief

SOGo, an open-source collaborative software server, is vulnerable to a security flaw in its password management system. When configured to use PostgreSQL or MariaDB with cleartext passwords, an attacker could manipulate database queries to gain unauthorized access to data or disrupt operations. Organizations using these specific database configurations should update to version 5.12.7 immediately to protect their user credentials and system integrity.

Technical details

An SQL injection vulnerability exists in SOGo's 'changePasswordForLogin' function within the SQLSource component. The root cause is the improper neutralization of special elements (CWE-89) when handling the 'c_password' field, specifically where the code used string formatting instead of proper SQL adaptors for parameterization. This vulnerability is exploitable when SOGo is configured with a PostgreSQL or MariaDB user source and 'userPasswordAlgorithm' is set to 'none', 'plain', or 'cleartext'. An authenticated attacker with low privileges could potentially execute arbitrary SQL commands to read, modify, or delete database content. The issue is resolved in version 5.12.7 by implementing proper SQL adaptors for user source queries.

Affected products

  • Alinto SOGo < 5.12.7

Timeline

  • 2026-03-24: patched: Fix committed to upstream repository
  • 2026-03-30: advisory: SOGo v5.12.7 released with security warning
  • 2026-05-14: disclosed: CVE-2026-46446 published

References

Related threats