Skip to main content
Vulnerability Database/CVE-2026-93453

CVE-2026-93453: SOGo Auth Bypass Vulnerability

CVE-2026-93453 is an authentication bypass flaw in SOGo that enables attackers to redirect password-reset tokens to malicious domains by manipulating the Origin header. This post covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-93453 Overview

CVE-2026-93453 is a password reset vulnerability [CWE-640] affecting SOGo groupware server versions before 5.12.11. The flaw allows unauthenticated attackers to intercept password recovery tokens by manipulating the HTTP Origin header during a password reset request. SOGo constructs the reset link using the client-supplied Origin header as the authority, sending victims links that point to attacker-controlled infrastructure. When a victim clicks the malicious link, the valid reset token is transmitted to the attacker, enabling full account takeover.

Critical Impact

Unauthenticated attackers can hijack SOGo accounts by tricking users into clicking password-reset links that leak valid tokens to attacker-controlled domains.

Affected Products

  • SOGo groupware server versions prior to 5.12.11
  • Deployments with SOGoPasswordRecoveryEnabled set to YES
  • All platforms running vulnerable SOGo builds (Linux distributions, container deployments)

Discovery Timeline

  • 2026-09-18 - CVE-2026-93453 published to the National Vulnerability Database
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-93453

Vulnerability Analysis

The vulnerability resides in the password reset workflow implemented in UI/MainUI/SOGoRootPage.m. When a user submits a password recovery request, SOGo constructs the reset URL by concatenating the request Origin header, the request URI, and the generated JWT token. The Origin header is entirely client-controlled and is never validated against a trusted list of hostnames.

An unauthenticated attacker submits a password recovery request for a victim account while injecting a custom Origin header pointing to attacker infrastructure. SOGo generates a valid password reset token and emails the victim a link where the authority points to the attacker's domain but the path and token remain valid. If the victim clicks the link, the attacker's server captures the token and can replay it against the legitimate SOGo instance to reset the password.

Root Cause

The root cause is improper trust of a client-supplied header when generating security-sensitive URLs. The vulnerable code in SOGoRootPage.m at line 1375 used [[request headers] objectForKey:@"origin"] as the URL authority. There was no allowlist of acceptable base URLs for password reset links, violating [CWE-640: Weak Password Recovery Mechanism for Forgotten Password].

Attack Vector

Exploitation requires no authentication and only a single HTTP request to the SOGo password recovery endpoint. The attacker must know or guess a valid target email address. Successful exploitation requires the victim to click the emailed link, which appears to originate from the legitimate SOGo service.

text
// Vulnerable code in UI/MainUI/SOGoRootPage.m (before fix)
          // Send mail
          mailer = [SOGoMailer mailerWithDomainDefaults: dd];
-          url = [NSString stringWithFormat:@"%@%@?token=%@"
-                      , [[request headers] objectForKey:@"origin"]
+
+          url = [NSString stringWithFormat:@"%@/%@?token=%@"
+                      , [[context serverURL] absoluteString]
                      , [request uri]
                      , jwtToken];

Source: SOGo Commit 382118a

Detection Methods for CVE-2026-93453

Indicators of Compromise

  • Password recovery HTTP requests containing an Origin header that does not match the configured SOGo hostname
  • Outbound password reset emails whose token URLs point to unexpected domains
  • Unusual spikes in requests to the SOGo password recovery endpoint from a single source IP
  • User reports of password reset emails they did not request

Detection Strategies

  • Inspect web server and reverse proxy logs for password recovery requests where the Origin header value is absent from the organization's approved domain list
  • Correlate password reset email generation events with subsequent successful password changes originating from unfamiliar IP addresses or geolocations
  • Alert on SOGo authentication events immediately following a password reset from a session that did not previously interact with the user's account

Monitoring Recommendations

  • Forward SOGo application logs and fronting reverse proxy logs to a centralized log platform for retention and analysis
  • Build detections that flag any HTTP request to /SOGo/so/ password recovery paths where Origin and Host headers diverge
  • Monitor mail server logs for outbound password reset emails and validate that embedded URLs resolve to authorized SOGo hostnames

How to Mitigate CVE-2026-93453

Immediate Actions Required

  • Upgrade SOGo to version 5.12.11 or later, which enforces server-side URL construction using [context serverURL] instead of the client Origin header
  • Configure the new SOGoPasswordRecoveryBaseURLs allowlist directive introduced in 5.12.11 with all legitimate SOGo hostnames
  • Invalidate any outstanding password reset tokens issued before the patch was applied
  • Review recent password change activity for signs of unauthorized account takeover

Patch Information

The upstream fix is delivered in SOGo v5.12.11. The patch replaces the client-controlled Origin header with the server-side context URL and adds the SOGoPasswordRecoveryBaseURLs configuration allowlist. Review the SOGo v5.12.11 Release Notes and the VulnCheck Advisory on SOGo for the full patch details. The commits are available at SOGo Commit 382118a and SOGo Commit 04a3e98.

Workarounds

  • Disable password recovery by setting SOGoPasswordRecoveryEnabled = NO; until the patch is deployed
  • Configure the fronting reverse proxy (nginx, Apache, HAProxy) to strip or overwrite the inbound Origin header on requests to the password recovery endpoint
  • Restrict access to the SOGo password recovery URL to trusted network ranges where feasible
bash
# Example sogo.conf configuration for SOGo 5.12.11 or later
SOGoPasswordRecoveryEnabled = YES;
SOGoPasswordRecoveryBaseURLs = ("https://mail.example.org");
# Do not end the URLs with a trailing slash.
# Multiple hostnames example:
# SOGoPasswordRecoveryBaseURLs = ("https://platform1.example.org", "https://platform2.example.org");

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.