Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ USN-8504-1 — sogo (CVE-2025-71276 +10 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

sogo vulnerabilities

It was discovered that SOGo did not properly sanitize categories used

for events, tasks, and contacts. A remote authenticated attacker could

possibly use this issue to perform cross-site scripting attacks. This

issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04

LTS, and Ubuntu 26.04 LTS. (CVE-2025-71276)

It was discovered that SOGo did not properly sanitize the hint query

parameter. A remote attacker could possibly use this issue to perform

cross-site scripting attacks. This issue only affected Ubuntu 26.04

LTS. (CVE-2026-3054)

It was discovered that SOGo did not renew the one-time password when a

user disabled and re-enabled it, and used a shorter length than

recommended. A remote attacker could possibly use this issue to bypass

authentication. This issue only affected Ubuntu 22.04 LTS and Ubuntu

26.04 LTS. (CVE-2026-33550)

It was discovered that SOGo did not properly use the SQL adaptor for

the user source, resulting in SQL injection when certain databases

were used. A remote authenticated attacker could possibly use this

issue to obtain sensitive information or execute arbitrary SQL

commands. (CVE-2026-46445, CVE-2026-46446)

It was discovered that SOGo did not properly sanitize mail containing

ICS calendar invitations. A remote attacker could possibly use this

issue to perform cross-site scripting attacks. This issue only

affected Ubuntu 26.04 LTS. (CVE-2026-8496)

It was discovered that SOGo did not properly validate identifiers when

managing access control lists. A remote authenticated attacker could

possibly use this issue to perform SQL injection attacks and obtain

sensitive information. (CVE-2026-8851)

It was discovered that SOGo did not properly sanitize the theme

parameter. A remote attacker could possibly use this issue to perform

cross-site scripting attacks. This issue only affected Ubuntu 18.04

LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2025-63499)

It was discovered that SOGo did not properly sanitize the userName

parameter on the login page. A remote attacker could possibly use this

issue to perform cross-site scripting attacks. This issue only

affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and

Ubuntu 22.04 LTS. (CVE-2025-63498)

It was discovered that SOGo did not properly sanitize attachments when

previewing them. A remote attacker could possibly use this issue to

perform cross-site scripting attacks. This issue only affected Ubuntu

16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

(CVE-2024-34462)

It was discovered that SOGo did not validate the signatures of SAML

assertions it received when SAML was used for authentication. A remote

attacker could possibly use this issue to impersonate other users.

This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and

Ubuntu 20.04 LTS. (CVE-2021-33054)

Affected software

USN-8504-1 is recorded against 1 package.

  • sogo (fixed in 5.12.4-1.2ubuntu0.1~esm1)

Timeline and source

Published on 5 July 2026 and last revised on 6 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Other advisories for this package

sogo has other advisories on record. If you are patching this one, these are worth checking on the same host:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-05
Updated 2026-08-20
Modified 2026-07-06
Fix URL N/A

Affected Packages

Software From version Fixed in
sogo 5.12.4-1.2ubuntu0.1~esm1

Similar Threats

Free Vulnerability Check

Is your site affected by USN-8504-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-8504-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesUbuntuUbuntu Undated