CVE-2026-33550

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
Configurations

Configuration 1 (hide)

cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*

History

23 Mar 2026, 19:57

Type Values Removed Values Added
First Time Alinto
Alinto sogo
CPE cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*
References () https://github.com/Alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2 - () https://github.com/Alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2 - Patch
References () https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.5 - () https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.5 - Release Notes

22 Mar 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-22 03:16

Updated : 2026-03-23 19:57


NVD link : CVE-2026-33550

Mitre link : CVE-2026-33550

CVE.ORG link : CVE-2026-33550


JSON object : View

Products Affected

alinto

  • sogo
CWE
CWE-308

Use of Single-factor Authentication