---
id: CVE-2026-74865
title: "sogo_yhn configures SOGo with a parameter \"SOGoTrustProxyAuthentication=YES\".\_This causes the password to be bypassed during HTTP Basic authentication"
summary: "sogo_yhn configures SOGo with a parameter \"SOGoTrustProxyAuthentication=YES\".\_This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arb…"
severity: critical
cvss: 9.2
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-639
vendor: YunoHost-Apps
product: sogo_yhn
affected:
  - sogo_yhn < 5.8.0~ynh9
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T13:17:20.083'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74865'
references:
  - url: 'https://cert.pl/en/posts/2026/09/CVE-2026-74864'
    label: cvd@cert.pl
  - url: >-
      https://forum.yunohost.org/t/sogo-critical-vulnerability-fixed-in-5-8-0-ynh9/42699
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-30T12:50:17.073137Z'
cvssSource: cna
ingestedAt: '2026-09-30T13:03:51.965Z'
---

## Overview

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.


This issue was fixed in version 5.8.0~ynh9.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
