External risk intelligence

SOGo HTTP Header Authentication Bypass Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-74864

SOGo is a groupware server commonly deployed as an internet-facing web application for email and calendar access. By design, these services are exposed to the internet to allow remote user connectivity, making the authentication portal and its headers a public-facing component.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in SOGo that could allow unauthorized access to user accounts without a password. The issue arises from how the system processes a specific HTTP header, potentially exposing sensitive information and system functions. The primary concern is to determine if your organization uses this technology and, if so, to assess the exposure.

  • Unauthorized password-free access is possible.
  • This affects internet-facing email and calendar services.
  • Confirm relevance and assess any potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can impersonate any user, including administrators, by sending a specially crafted HTTP request to the SOGo server. This is possible because the server, with the help of Nginx, incorrectly trusts the "x-webobjects-remote-user" header, bypassing the need for password authentication. Successfully exploiting this vulnerability could allow an attacker to access and modify sensitive data, or perform administrative actions on behalf of legitimate users.

  • No authentication required to send request.
  • HTTP header triggers unauthorized access.
  • Risk of account takeover and data breaches.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to impersonate any user, including administrators, by sending a specially crafted HTTP request. This bypasses password validation when SOGo is configured with a specific parameter and Nginx is used as a reverse proxy.

  • User account access
  • Via specially crafted HTTP header
  • Unauthorized access to user data

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams are likely responsible for addressing this critical vulnerability in SOGo. The first practical step is to identify all SOGo instances, confirm their exposure and business criticality, and then identify the accountable owner for each. Remediation planning should be risk-based, considering factors like reachability and the criticality of the affected systems.

  • Application owners should manage the issue.
  • Verify SOGo instance reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SOGo and how is it used?

SOGo is a collaboration software suite that functions as a groupware server. Organizations commonly deploy it to manage email, calendar, and address book services, providing a centralized platform for users to access their communication data through web-based interfaces.

What is the vulnerability in CVE-2026-74864?

This vulnerability is classified as an authorization bypass, specifically CWE-639. It occurs because the system incorrectly trusts an incoming HTTP header to identify the user. By accepting this header without verifying the user's password, the software fails to confirm identity, allowing anyone to bypass the standard authentication process entirely.

How can an attacker trigger this bug?

An attacker triggers the vulnerability by sending a web request that includes a specifically crafted 'x-webobjects-remote-user' HTTP header. Because the software assumes this header is pre-validated, it grants access based on the username provided in the header. Requests that lack this specific header or are sent to services not configured with the vulnerable parameter do not trigger this bypass.

Is my SOGo instance at risk?

Halo Surface Signal notes that SOGo is frequently deployed as an internet-facing application to support remote access. If your server is reachable over the public internet, it is inherently exposed to these requests. Instances restricted to internal-only networks face a lower profile, but they remain susceptible if an attacker gains any foothold within your network.

How do I secure my SOGo deployment?

The most effective response is to update your SOGo installation to version 5.8.0~ynh9 or later, which contains the necessary fix. Before updating, you should audit your infrastructure to locate all active SOGo instances, confirm their specific version numbers, and verify whether they are reachable from the internet to prioritize your remediation efforts.

References