CVE-2026-93453

CVE-2026-93453 published: SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with...

View full NVD advisory → ← Back to CVE watch