← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 00:17via CVEFeed

CVE-2026-93453 - SOGo before 5.12.11 Password Reset Token Interception via Origin Header

Brief

CVE ID : CVE-2026-93453

Published : Sept. 18, 2026, 12:17 a. m.

  • 38 minutes ago

Description : SOGo before 5.

  • 11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains.

Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.

Severity: 8.7

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→