This issue was fixed in version 5.8.0~ynh9.
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password. This issue was fixed in version 5.8.0~ynh9. | |
| Title | Authentication Bypass in sogo_yhn | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-30T12:50:52.363Z
Reserved: 2026-08-17T10:19:51.723Z
Link: CVE-2026-74864
Updated: 2026-09-30T12:50:49.501Z
Status : Deferred
Published: 2026-09-30T13:17:19.913
Modified: 2026-09-30T19:57:08.043
Link: CVE-2026-74864
No data.
OpenCVE Enrichment
Updated: 2026-09-30T13:30:17Z