OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-74865 (CVSS 9.2)

NVD · officialPublished Sep 30, 2026Risk 50/100

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.

CVSS
9.2
AV:NetworkAC:HighPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source