CVE WATCH / VULNERABILITY DETAIL

CVE-2026-74865

UNKNOWNCVSS 0NVD feed

Published 30 September 2026 · tracked since 1 October 2026

Description

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-74865 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-74865

UNKNOWNCVSS 0NVD feed

Published 30 September 2026 · tracked since 1 October 2026

Description

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]