{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sogo--5.12.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-93453"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=8D42E2DA-4559-5F60-A8C3-DF95BE8B7FD0\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["SOGo (\u003c 5.12.11)","SOGo (\u003c= 5.12.10)"],"_cs_severities":["high"],"_cs_tags":["web-application","credential-theft","cve-2026-93453"],"_cs_type":"advisory","_cs_vendors":["Alinto"],"content_html":"\u003cp\u003eCVE-2026-93453 affects SOGo, a collaborative software suite, in versions prior to 5.12.11. The vulnerability exists due to improper input validation where the application uses the client-supplied 'Origin' HTTP header to construct the base URL for password-reset links sent via email.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can exploit this by initiating a password-reset request for a target user account while simultaneously providing a crafted 'Origin' header in the HTTP request. The SOGo backend fails to sanitize this input, resulting in the generation of a legitimate reset token delivered to the user, but embedded within a URL pointing to an attacker-controlled server. If the victim clicks this link, the recovery token is leaked to the attacker's server, facilitating full account takeover. This flaw is particularly impactful for organizations relying on SOGo for email and calendar management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to hijack user accounts by capturing password-reset tokens. This vulnerability poses a severe risk to organizational security, potentially leading to unauthorized access to sensitive internal communications, calendars, and organizational data. The impact is elevated given that the attack is unauthenticated and can be automated to target multiple users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade SOGo to version 5.12.11 or later immediately to patch CVE-2026-93453.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or server-side configuration for the expected 'Origin' and 'Host' headers within the web server reverse proxy configuration (e.g., nginx or Apache) to drop requests with unauthorized headers.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous 'Origin' header values during password reset requests.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T09:27:01Z","date_published":"2026-09-18T02:01:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sogo-reset-poisoning/","summary":"SOGo versions before 5.12.11 are vulnerable to password reset poisoning, allowing unauthenticated attackers to manipulate reset links by injecting malicious values into the Origin header.","title":"CVE-2026-93453 Password Reset Poisoning in SOGo","url":"https://feed.craftedsignal.io/briefs/2026-09-sogo-reset-poisoning/"}],"language":"en","title":"CraftedSignal Threat Feed - SOGo (\u003c 5.12.11)","version":"https://jsonfeed.org/version/1.1"}