| CVE ID | CVE-2026-74864 |
| Publication date | 30 September 2026 |
| Vendor | YunoHost-Apps |
| Product | sogo_yhn |
| Vulnerable versions | All before 5.8.0~ynh9 |
| Vulnerability type (CWE) | Authorization bypass through User-Controlled key (CWE-639) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-74865 |
| Publication date | 30 September 2026 |
| Vendor | YunoHost-Apps |
| Product | sogo_yhn |
| Vulnerable versions | All before 5.8.0~ynh9 |
| Vulnerability type (CWE) | Authorization bypass through User-Controlled key (CWE-639) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in YunoHost-Apps sogo_yhn software and participated in coordination of their disclosure.
The vulnerability CVE-2026-74864: sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password.
The vulnerability CVE-2026-74865: sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account.
These issues were fixed in version 5.8.0~ynh9.
Credits
We thank Przemysław Knycz from WeKrwi.IT (https://github.com/djrzulf) for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.