Cross-Site Scripting Vulnerability in Alinto SOGo Webmail
CVE-2026-8496

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-8496?

A cross-site scripting vulnerability exists in Alinto SOGo version 5.12.7, allowing for arbitrary JavaScript execution within the webmail interface. This vulnerability arises when SVG content embedded in the description field of an ICS calendar invitation is inadequately sanitized. A remote attacker can exploit this issue to execute JavaScript in the victim's browser during the viewing of a malicious calendar invite. Successful exploitation may lead to unauthorized access to the mailbox, theft of emails and contacts, session hijacking, and other actions that an authenticated user is permitted to perform.

Affected Version(s)

SOGo 0 < 5.12.8

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.