CVE-2026-8496

EUVD-2026-30134
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version  5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS file, with an onrepeat event handler, is insufficiently sanitized before being rendered in the webmail interface. A remote attacker can execute JavaScript in the victim's browser when the malicious calendar invite is viewed.  Successful exploitation may allow mailbox access, email and contact theft, session hijacking, and other actions allowed by an authenticated user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 33.68%
Debian logo
Debian Releases
Debian Product
Codename
sogo
bookworm
5.8.0-2+deb12u3
fixed
bookworm (security)
5.8.0-2+deb12u3
fixed
bullseye
ignored
bullseye (security)
vulnerable
forky
5.12.9-1
fixed
sid
5.12.9-1
fixed
trixie
5.12.1-3+deb13u2
fixed
trixie (security)
5.12.1-3+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sogo
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
questing
ignored
resolute
Fixed 5.12.4-1.2ubuntu0.1~esm1
released