CVE-2026-74865

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,2
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

sogo_yhn configures SOGo with a parameter 'SOGoTrustProxyAuthentication=YES'. This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.

This issue was fixed in version 5.8.0~ynh9.

639

Authorization Bypass Through User-Controlled Key

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
https://cert.pl/en/posts/2026/09/CVE-2026-74864
https://forum.yunohost.org/t/sogo-critical-vulnerability-fixed-in-5-8-0-ynh9/42…