CVE-2026-33550

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
Configurations

Configuration 1 (hide)

cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-22 03:16

Updated : 2026-03-23 19:57


NVD link : CVE-2026-33550

Mitre link : CVE-2026-33550

CVE.ORG link : CVE-2026-33550


JSON object : View

Products Affected

alinto

  • sogo
CWE
CWE-308

Use of Single-factor Authentication