SQL Injection Vulnerability in SOGo by Alinto
CVE-2026-39179
6.3MEDIUM
What is CVE-2026-39179?
A SQL injection vulnerability exists in SOGo versions prior to 5.12.7, enabling authenticated users to execute arbitrary SQL queries through the newPassword parameter in the password change interface, potentially compromising the integrity and confidentiality of the database.
