CVE-2026-74864
sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password. This issue was fixed in version 5.8.0~ynh9.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.41%
- CWE
- CWE-639
- Published
- 2026-09-30
- Last modified
- 2026-09-30
Affected products
- YunoHost-Apps sogo_yhn
Weakness type
Related vulnerabilities
- CVE-2026-103009 — Authorization Bypass Through User-Controlled Key in Elasticsearch Leading to Information Disclosure
- CVE-2026-105859 — Payload: Unauthorized update to collection documents
- CVE-2026-105639 — Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane
- CVE-2026-105637 — Plane: Cross-Project Asset Hijacking via 'ProjectBulkAssetEndpoint' (sibling of CVE-2026-46558)
- CVE-2026-91107 — openSIS Classic 9.3 - Insecure Direct Object Reference (IDOR)
- CVE-2026-101084 — obot before v0.21.1 Authorization Bypass via /mcp-connect
- CVE-2026-74865 — Authentication Bypass in sogo_yhn
- CVE-2026-93399 — Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter