This issue was fixed in version 5.8.0~ynh9.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password. This issue was fixed in version 5.8.0~ynh9. | |
| Title | Authentication Bypass in sogo_yhn | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-30T12:50:52.363Z
Reserved: 2026-08-17T10:19:51.723Z
Link: CVE-2026-74864
Updated: 2026-09-30T12:50:49.501Z
Status : Deferred
Published: 2026-09-30T13:17:19.913
Modified: 2026-09-30T19:57:08.043
Link: CVE-2026-74864
No data.
OpenCVE Enrichment
Updated: 2026-09-30T13:30:17Z
-
CWE-639
Authorization Bypass Through User-Controlled Key