Junglewise Threat Intelligence

CVE-2026-93453: SOGo password-reset link injection via Origin header

CVE-2026-93453 · Severity: high · CVSS 8.3 · Published 2026-09-18

Technologies: Alinto Sogo. Vendors: Alinto.

Executive brief

SOGo is a groupware collaboration platform that provides email, calendar, and contact management for organizations. The application constructs password-reset links using an untrusted client-supplied Origin header, allowing unauthenticated attackers to craft malicious password-recovery requests that send legitimate password-reset tokens to attacker-controlled domains, enabling account takeover of any user account.

Technical details

The vulnerability is an open redirect / header injection flaw in SOGo's password-reset token generation mechanism. During password recovery, the application constructs the password-reset URL using the Origin header supplied by the client without proper validation, allowing an attacker to inject an arbitrary domain. An unauthenticated attacker can submit a password-recovery request with a malicious Origin header; the legitimate password-reset token will then be emailed within a link pointing to the attacker's infrastructure. When the victim clicks the link, the token is leaked to the attacker, who can then reset the victim's password and gain full account access. The flaw affects SOGo versions before 5.12.11 and requires no authentication. A patch is available in version 5.12.11 and later.

Affected products

  • Alinto SOGo before 5.12.11

Timeline

  • 2026-09-18: disclosed

References

Related threats