{"id":"CVE-2026-33550","details":"SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).","modified":"2026-08-12T15:33:25.223988Z","published":"2026-03-22T02:16:56.263Z","database_specific":{"cwe_ids":["CWE-308"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33550.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33550.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33550"},{"type":"FIX","url":"https://github.com/Alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alinto/sogo","events":[{"introduced":"0"},{"fixed":"7f7e1ad496c626ac1fbb1020f20f08f9efccc06b"},{"fixed":"83d4c522f87cfde0ba543837d9b24c3479083ec2"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.12.5"}]}}],"versions":["SOGo-5.12.4","SOGo-5.12.1","SOGo-5.12.3","SOGo-5.12.2","SOGo-5.12.0","SOGo-5.11.2","SOGo-5.11.0","SOGo-5.11.1","SOGo-5.10.0","SOGo-5.9.0","SOGo-5.8.2","SOGo-5.8.1","SOGo-5.8.0","SOGo-5.7.1","SOGo-5.7.0","SOGo-5.6.0","SOGo-5.5.1","SOGo-5.5.0","SOGo-5.4.0","SOGo-5.3.0","SOGo-5.2.0","SOGo-5.1.1","SOGo-5.1.0","SOGo-5.0.1","SOGo-5.0.0","SOGo-4.3.2","SOGo-4.3.1","SOGo-4.3.0","SOGo-4.2.0","SOGo-4.1.1","SOGo-4.1.0","SOGo-4.0.8","SOGo-4.0.7","SOGo-4.0.6","SOGo-4.0.5","SOGo-4.0.4","SOGo-4.0.3","SOGo-4.0.2","SOGo-4.0.1","SOGo-4.0.0","SOGo-3.2.10","SOGo-3.2.9","SOGo-3.2.8","SOGo-3.2.7","SOGo-3.2.6a","SOGo-3.2.5","SOGo-3.2.4","SOGo-3.2.3","SOGo-3.2.2","SOGo-3.2.1","SOGo-3.2.0","SOGo-3.1.5","SOGo-3.1.4","SOGo-3.1.3","SOGo-3.1.2","SOGo-3.1.0","SOGo-3.0.2","SOGo-3.0.1","SOGo-3.0.0","SOGo-3.0.0b5","SOGo-3.0.0b4","SOGo-3.0.0b3","SOGo-3.0.0b2","SOGo-3.0.0b1","SOGo-2.3.0","SOGo-2.2.17a","SOGo-2.2.20","SOGo-2.0.2","SOGo-2.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33550.json","vanir_signatures_modified":"2026-08-12T15:33:25Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["210430912351680258099012889449626424136","118547479593593158927144485846800927963","52033065985110991692933028964535079607","78940714658635439390355102182641246101"],"threshold":0.9},"id":"CVE-2026-33550-8d4b411e","signature_type":"Line","signature_version":"v1","source":"https://github.com/alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2","target":{"file":"SoObjects/SOGo/SOGoUser.h"}},{"id":"CVE-2026-33550-c755e580","signature_type":"Line","signature_version":"v1","source":"https://github.com/alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2","target":{"file":"SoObjects/SOGo/SOGoUserSettings.h"},"deprecated":false,"digest":{"line_hashes":["177686447049141624995183196277635006705","89741928345062303720684782183649812723","132955516672192288287528512238777328059","174630184015155944436707833403087040168"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N"}]}