SQL Injection Vulnerability in SOGo by Alinto
CVE-2026-8851

8.6HIGH

Key Information:

Vendor

Alinto

Vendor
CVE Published:
18 May 2026

What is CVE-2026-8851?

SOGo version 5.12.7 has a SQL injection vulnerability affecting its Access Control List management. Authenticated users can exploit this flaw by injecting SQL code via the uid parameter of the addUserInAcls endpoint. This attack allows unauthorized extraction of data from the database, as attackers can manipulate SQL queries to read sensitive data stored in the sogo_acl table and access it through the /acls API, potentially creating an out-of-band data exfiltration channel.

Affected Version(s)

SOGo Webmail 5.12.8

SOGo Webmail 0 <= 5.12.7

SOGo Webmail 5.12.8

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dninh of SACOMBANK
.