CVE-2026-93453 - SOGo before 5.12.11 Password Reset Token Interception via Origin Header
Brief
CVE ID : CVE-2026-93453
Published : Sept. 18, 2026, 12:17 a. m.
- 38 minutes ago
Description : SOGo before 5.
- 11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains.
Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.
Severity: 8.7
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
