CVE-2026-3054
published 2026-02-24CVE-2026-3054: A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site…
PriorityP433medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.40%
32.5th percentile
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| alinto | sogo | — | — |
| alinto | sogo | — | — |
| alinto | sogo | >= 0 < 5.12.6-1 | 5.12.6-1 |
| debian | sogo | < sogo 5.12.6-1 (forky) | sogo 5.12.6-1 (forky) |
| ubuntu | sogo | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-47ph-5j6m-fmgx: A vulnerability was identified in Alinto SOGo 5
ghsa_unreviewed·2026-02-24
CVE-2026-3054 [MEDIUM] CWE-79 GHSA-47ph-5j6m-fmgx: A vulnerability was identified in Alinto SOGo 5
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
OSV
CVE-2026-3054: A vulnerability was identified in Alinto SOGo 5
osv·2026-02-24·CVSS 5.3
CVE-2026-3054 [MEDIUM] CVE-2026-3054: A vulnerability was identified in Alinto SOGo 5
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Ubuntu
SOGo vulnerabilities
vendor_ubuntu·2026-07-05·CVSS 6.1
CVE-2026-8851 [MEDIUM] SOGo vulnerabilities
Title: SOGo vulnerabilities
Summary: Several security issues were fixed in SOGo.
It was discovered that SOGo did not properly sanitize categories used
for events, tasks, and contacts. A remote authenticated attacker could
possibly use this issue to perform cross-site scripting attacks. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 26.04 LTS. (CVE-2025-71276)
It was discovered that SOGo did not properly sanitize the hint query
parameter. A remote attacker could possibly use this issue to perform
cross-site scripting attacks. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-3054)
It was discovered that SOGo did not renew the one-time password when a
user disabled and re-enabled it, and used a shorter length than
recommended. A remote attack
Debian
CVE-2026-3054: sogo - A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unk...
vendor_debian·2026·CVSS 5.3
CVE-2026-3054 [MEDIUM] CVE-2026-3054: sogo - A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unk...
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.12.6-1)
sid: resolved (fixed in 5.12.6-1)
trixie: open
No detection rules found.
No public exploits indexed.
2026-02-24
Published