SQL Injection Vulnerability in SOGo Web Application by Alinto
CVE-2026-46445

7.1HIGH

Key Information:

Vendor

Alinto

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-46445?

A vulnerability found in SOGo versions prior to 5.12.7 exposes the application to SQL injection when using PostgreSQL as the backend database. This flaw enables attackers to manipulate SQL queries, potentially allowing unauthorized access to sensitive data stored within the application. Organizations utilizing SOGo must take immediate action to update to the latest version to mitigate the risk associated with this vulnerability, ensuring their data remains secure from potential exploitation.

Affected Version(s)

SOGo 0 < 5.12.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.