SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
CVSS Details
- CVSS 3.1 Base Score: 2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade sogo | Jul 1, 2026 | Jul 1, 2026 |
| Ubuntu | — | Upgrade sogo-activesync (Ubuntu Pro)Upgrade sogo (Ubuntu Pro)Upgrade sogo-common (Ubuntu Pro) | Jul 6, 2026 | Mar 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub