Executive brief
SOGo, an open-source collaborative software server, contains a security flaw in its access control management system. An authorized user can exploit this vulnerability to bypass security restrictions and extract sensitive information from the underlying database. This could lead to the theft of user credentials, private communications, or other confidential organizational data stored within the mail and calendar system.
Technical details
A SQL injection vulnerability exists in SOGo versions 5.12.7 and earlier within the Access Control List (ACL) management functionality. The flaw is located in the 'addUserInAcls' endpoint, where the 'uid' parameter is improperly neutralized before being used in a database query. An authenticated attacker can inject malicious SQL subqueries to extract arbitrary data from the database. By writing the results of these subqueries into the 'sogo_acl' table, the attacker can subsequently retrieve the stolen data via the '/acls' API, effectively creating an out-of-band exfiltration channel. The issue is resolved in version 5.12.8.
Affected products
- Alinto SOGo <= 5.12.7
Timeline
- 2026-05-12: patched: SOGo version 5.12.8 released to address the vulnerability.
- 2026-05-18: disclosed: CVE-2026-8851 published.