CVE-2026-93453 Overview
CVE-2026-93453 is a password reset vulnerability [CWE-640] affecting SOGo groupware server versions before 5.12.11. The flaw allows unauthenticated attackers to intercept password recovery tokens by manipulating the HTTP Origin header during a password reset request. SOGo constructs the reset link using the client-supplied Origin header as the authority, sending victims links that point to attacker-controlled infrastructure. When a victim clicks the malicious link, the valid reset token is transmitted to the attacker, enabling full account takeover.
Critical Impact
Unauthenticated attackers can hijack SOGo accounts by tricking users into clicking password-reset links that leak valid tokens to attacker-controlled domains.
Affected Products
- SOGo groupware server versions prior to 5.12.11
- Deployments with SOGoPasswordRecoveryEnabled set to YES
- All platforms running vulnerable SOGo builds (Linux distributions, container deployments)
Discovery Timeline
- 2026-09-18 - CVE-2026-93453 published to the National Vulnerability Database
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-93453
Vulnerability Analysis
The vulnerability resides in the password reset workflow implemented in UI/MainUI/SOGoRootPage.m. When a user submits a password recovery request, SOGo constructs the reset URL by concatenating the request Origin header, the request URI, and the generated JWT token. The Origin header is entirely client-controlled and is never validated against a trusted list of hostnames.
An unauthenticated attacker submits a password recovery request for a victim account while injecting a custom Origin header pointing to attacker infrastructure. SOGo generates a valid password reset token and emails the victim a link where the authority points to the attacker's domain but the path and token remain valid. If the victim clicks the link, the attacker's server captures the token and can replay it against the legitimate SOGo instance to reset the password.
Root Cause
The root cause is improper trust of a client-supplied header when generating security-sensitive URLs. The vulnerable code in SOGoRootPage.m at line 1375 used [[request headers] objectForKey:@"origin"] as the URL authority. There was no allowlist of acceptable base URLs for password reset links, violating [CWE-640: Weak Password Recovery Mechanism for Forgotten Password].
Attack Vector
Exploitation requires no authentication and only a single HTTP request to the SOGo password recovery endpoint. The attacker must know or guess a valid target email address. Successful exploitation requires the victim to click the emailed link, which appears to originate from the legitimate SOGo service.
// Vulnerable code in UI/MainUI/SOGoRootPage.m (before fix)
// Send mail
mailer = [SOGoMailer mailerWithDomainDefaults: dd];
- url = [NSString stringWithFormat:@"%@%@?token=%@"
- , [[request headers] objectForKey:@"origin"]
+
+ url = [NSString stringWithFormat:@"%@/%@?token=%@"
+ , [[context serverURL] absoluteString]
, [request uri]
, jwtToken];
Source: SOGo Commit 382118a
Detection Methods for CVE-2026-93453
Indicators of Compromise
- Password recovery HTTP requests containing an Origin header that does not match the configured SOGo hostname
- Outbound password reset emails whose token URLs point to unexpected domains
- Unusual spikes in requests to the SOGo password recovery endpoint from a single source IP
- User reports of password reset emails they did not request
Detection Strategies
- Inspect web server and reverse proxy logs for password recovery requests where the Origin header value is absent from the organization's approved domain list
- Correlate password reset email generation events with subsequent successful password changes originating from unfamiliar IP addresses or geolocations
- Alert on SOGo authentication events immediately following a password reset from a session that did not previously interact with the user's account
Monitoring Recommendations
- Forward SOGo application logs and fronting reverse proxy logs to a centralized log platform for retention and analysis
- Build detections that flag any HTTP request to /SOGo/so/ password recovery paths where Origin and Host headers diverge
- Monitor mail server logs for outbound password reset emails and validate that embedded URLs resolve to authorized SOGo hostnames
How to Mitigate CVE-2026-93453
Immediate Actions Required
- Upgrade SOGo to version 5.12.11 or later, which enforces server-side URL construction using [context serverURL] instead of the client Origin header
- Configure the new SOGoPasswordRecoveryBaseURLs allowlist directive introduced in 5.12.11 with all legitimate SOGo hostnames
- Invalidate any outstanding password reset tokens issued before the patch was applied
- Review recent password change activity for signs of unauthorized account takeover
Patch Information
The upstream fix is delivered in SOGo v5.12.11. The patch replaces the client-controlled Origin header with the server-side context URL and adds the SOGoPasswordRecoveryBaseURLs configuration allowlist. Review the SOGo v5.12.11 Release Notes and the VulnCheck Advisory on SOGo for the full patch details. The commits are available at SOGo Commit 382118a and SOGo Commit 04a3e98.
Workarounds
- Disable password recovery by setting SOGoPasswordRecoveryEnabled = NO; until the patch is deployed
- Configure the fronting reverse proxy (nginx, Apache, HAProxy) to strip or overwrite the inbound Origin header on requests to the password recovery endpoint
- Restrict access to the SOGo password recovery URL to trusted network ranges where feasible
# Example sogo.conf configuration for SOGo 5.12.11 or later
SOGoPasswordRecoveryEnabled = YES;
SOGoPasswordRecoveryBaseURLs = ("https://mail.example.org");
# Do not end the URLs with a trailing slash.
# Multiple hostnames example:
# SOGoPasswordRecoveryBaseURLs = ("https://platform1.example.org", "https://platform2.example.org");
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
