{"id":"CVE-2026-93453","title":"SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains","summary":"SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password re…","severity":"high","cvss":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","cwe":["CWE-640"],"vendor":"Alinto","product":"SOGo","affected":["SOGo < 5.12.11"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:18:26.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93453","references":[{"url":"https://github.com/Alinto/sogo","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Alinto/sogo/blob/SOGo-5.12.10/UI/MainUI/SOGoRootPage.m#L1375","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Alinto/sogo/commit/04a3e9823889acaf6c247b224f5f7a0108f8f829","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Alinto/sogo/commit/382118a93b6925de2ce7f774abc1865ebea2dbba","label":"disclosure@vulncheck.com"},{"url":"https://www.sogo.nu/news/2026/sogo-v51211-released.html","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sogo-before-5.12.11-password-reset-token-interception-via-origin-header","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T18:02:33.954501Z"},"epss":0.00344,"epssPercentile":0.27937,"exploits":{"github":1,"githubRepos":["https://github.com/Faceless0x7/CVE-2026-93453"],"checkedAt":"2026-09-21T15:31:30.617Z"},"exploitAvailable":true,"ingestedAt":"2026-09-17T23:31:20.691Z","slug":"CVE-2026-93453","body":"## Overview\n\nSOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":58,"depthScoreParts":{"impact":45.7,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":207426,"id":"CVE-2026-93453","ts":1789757348058,"field":"exploit_available","old":"false","new":"true"}]}