OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-74865

CRITICAL · CVSS 9.2 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to bypass HTTP Basic authentication in SOGo by exploiting the "SOGoTrustProxyAuthentication=YES" configuration, enabling them to log in as any existing user using any password. This critical security flaw poses a significant risk to user accounts and sensitive data. Organizations using affected versions should prioritize immediate updates to version 5.8.0~ynh9 to mitigate potential breaches.

CVE
CVE-2026-74865
Severity
CRITICAL
CVSS
9.2
EPSS
0.38%

Original NVD Description

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.