{"id":"CVE-2026-93453","summary":"SOGo before 5.12.11 Password Reset Token Interception via Origin Header","details":"SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.","modified":"2026-09-19T08:03:45.445358Z","published":"2026-09-17T23:25:12.890Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93453.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-640"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93453.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93453"},{"type":"ADVISORY","url":"https://www.sogo.nu/news/2026/sogo-v51211-released.html"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/sogo-before-5.12.11-password-reset-token-interception-via-origin-header"},{"type":"FIX","url":"https://github.com/Alinto/sogo/commit/04a3e9823889acaf6c247b224f5f7a0108f8f829"},{"type":"FIX","url":"https://github.com/Alinto/sogo/commit/382118a93b6925de2ce7f774abc1865ebea2dbba"},{"type":"PACKAGE","url":"https://github.com/Alinto/sogo"},{"type":"ARTICLE","url":"https://github.com/Alinto/sogo/blob/SOGo-5.12.10/UI/MainUI/SOGoRootPage.m#L1375"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alinto/sogo","events":[{"introduced":"0"},{"fixed":"c0a83f5c3554d5ce31850bc7abc3a3f04b03abe3"},{"fixed":"04a3e9823889acaf6c247b224f5f7a0108f8f829"},{"fixed":"382118a93b6925de2ce7f774abc1865ebea2dbba"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"5.12.11"}]}}],"versions":["SOGo-5.12.10","SOGo-5.12.8","SOGo-5.12.7","SOGo-5.12.6","SOGo-5.12.5","SOGo-5.12.4","SOGo-5.12.1","SOGo-5.12.3","SOGo-5.12.2","SOGo-5.12.0","SOGo-5.11.2","SOGo-5.11.0","SOGo-5.11.1","SOGo-5.10.0","SOGo-5.9.0","SOGo-5.8.2","SOGo-5.8.1","SOGo-5.8.0","SOGo-5.7.1","SOGo-5.7.0","SOGo-5.6.0","SOGo-5.5.1","SOGo-5.5.0","SOGo-5.4.0","SOGo-5.3.0","SOGo-5.2.0","SOGo-5.1.1","SOGo-5.1.0","SOGo-5.0.1","SOGo-5.0.0","SOGo-4.3.2","SOGo-4.3.1","SOGo-4.3.0","SOGo-4.2.0","SOGo-4.1.1","SOGo-4.1.0","SOGo-4.0.8","SOGo-4.0.7","SOGo-4.0.6","SOGo-4.0.5","SOGo-4.0.4","SOGo-4.0.3","SOGo-4.0.2","SOGo-4.0.1","SOGo-4.0.0","SOGo-3.2.10","SOGo-3.2.9","SOGo-3.2.8","SOGo-3.2.7","SOGo-3.2.6a","SOGo-3.2.5","SOGo-3.2.4","SOGo-3.2.3","SOGo-3.2.2","SOGo-3.2.1","SOGo-3.2.0","SOGo-3.1.5","SOGo-3.1.4","SOGo-3.1.3","SOGo-3.1.2","SOGo-3.1.0","SOGo-3.0.2","SOGo-3.0.1","SOGo-3.0.0","SOGo-3.0.0b5","SOGo-3.0.0b4","SOGo-3.0.0b3","SOGo-3.0.0b2","SOGo-3.0.0b1","SOGo-2.3.0","SOGo-2.2.17a","SOGo-2.2.20","SOGo-2.0.2","SOGo-2.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93453.json","vanir_signatures_modified":"2026-09-19T08:03:45Z","vanir_signatures":[{"target":{"file":"SoObjects/SOGo/SOGoSystemDefaults.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["225942381120307779212702195603196938395","78201249962957314865711573196513007782","99580188145299495242851591184750488134","263398982896022421337082381569175600772"]},"id":"CVE-2026-93453-83a426eb","signature_type":"Line","signature_version":"v1","source":"https://github.com/alinto/sogo/commit/04a3e9823889acaf6c247b224f5f7a0108f8f829"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"}]}