CRITICAL 9.2 NVD

CVE-2026-74865

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unaut

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.

References

Published: 2026-09-30 · Source: NVD · Feed updated: 2026-09-30
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-09-30 via NVD.

Risk Timeline

CVE Disclosed2026-09-30 · -1 days ago

Remediation Resources

vulnfeed aggregates 9449 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.