SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
References
| Link | Resource |
|---|---|
| https://github.com/Alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2 | Patch |
| https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.5 | Release Notes |
Configurations
History
No history.
Information
Published : 2026-03-22 03:16
Updated : 2026-03-23 19:57
NVD link : CVE-2026-33550
Mitre link : CVE-2026-33550
CVE.ORG link : CVE-2026-33550
JSON object : View
Products Affected
alinto
- sogo
CWE
CWE-308
Use of Single-factor Authentication
