CVE-2026-74865 PUBLISHED

Authentication Bypass in sogo_yhn

Assigner: CERT-PL
Reserved: 17.08.2026 Published: 30.09.2026 Updated: 30.09.2026

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.

This issue was fixed in version 5.8.0~ynh9.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor YunoHost-Apps
Product sogo_yhn
Versions Default: unaffected
  • affected from 0 to 5.8.0~ynh9 (excl.)

Credits

  • Przemysław Knycz WeKrwi.IT https://github.com/djrzulf finder

References

Problem Types

  • CWE-639 Authorization bypass through User-Controlled key CWE