CVE-2026-46446
EUVD-2026-3021314.05.2026, 04:17
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| alinto | sogo | 𝑥 < 5.12.7 | CNA |
Debian Releases