External risk intelligence

SOGo HTTP Basic Authentication Password Bypass Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-74865

SOGo is a groupware server commonly deployed to provide webmail, calendar, and contact services to users. These services are designed to be accessible over the public internet to facilitate remote access for organizational users, placing the authentication interface directly in the path of internet-based traffic.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in SOGo, a groupware solution, where a misconfiguration can allow unauthenticated attackers to bypass password checks and access user accounts. This could expose sensitive information within those accounts.

  • Password bypass allows unauthorized account access.
  • Exposes sensitive user information and services.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could bypass SOGo's HTTP Basic authentication by sending a request with an existing user's username and any password when the `SogoTrustProxyAuthentication` parameter is incorrectly configured. This allows the attacker to log in to the targeted user's account.

  • Network access required.
  • Bypasses HTTP Basic authentication.
  • Account takeover.

Live Threat

Current exploitation, exposure, and threat context

When SOGo is configured with `SogoTrustProxyAuthentication=YES`, an unauthenticated attacker could bypass HTTP Basic authentication by providing a valid username and any password to log into a user's account. This could expose user account data and service functionality to unauthorized access.

  • User account data and service functionality.
  • Bypassing authentication with valid username.
  • Unauthorized access to user accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability bypasses authentication, allowing unauthorized access to user accounts. The primary responsibility for addressing this lies with the platform or infrastructure team managing SOGo, in coordination with security teams to assess and mitigate exposure. The initial step is to identify all SOGo instances, confirm their accessibility and criticality, and then plan remediation based on the identified risk.

  • Platform or infrastructure teams own the issue.
  • Verify SOGo instance accessibility and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SOGo and how is it typically used?

SOGo is a groupware server software package that serves as a central hub for organizational communication. It provides web-based access to email, shared calendars, and contact management tools. Organizations use it to keep distributed teams connected and synchronized. Because these features are essential for remote work, it is common to deploy SOGo where it can be accessed over the internet, allowing users to reach their messages and schedules from any location.

What is the vulnerability in CVE-2026-74865?

CVE-2026-74865 is a critical authentication bypass vulnerability, classified as CWE-639. It occurs because a specific configuration setting, when enabled, causes the system to incorrectly trust incoming proxy authentication requests. This flaw effectively disables the password verification step for HTTP Basic authentication. Consequently, the application will accept any password provided, provided the attacker supplies a username that already exists in the system.

How does an attacker trigger this SOGo authentication bypass?

The flaw is triggered when the SOGo configuration parameter 'SOGoTrustProxyAuthentication' is set to 'YES'. When this is active, an attacker does not need legitimate credentials to gain access. They only need to know a valid username for the target system. Simply submitting that username with any arbitrary password string in an HTTP request allows the system to grant them access to that user's account. Standard login attempts with correct passwords are not required.

Who should prioritize fixing this vulnerability?

Any organization running SOGo should consider this a high priority, especially those with internet-facing deployments. According to Halo Surface Signal, because SOGo is frequently exposed to the public internet to support remote users, the authentication interface is directly reachable by external actors. If your SOGo instance is reachable from the internet, it is effectively in the path of potential traffic from unauthorized users, significantly increasing the risk of this flaw.

What should I do if I am running SOGo?

Start by identifying all SOGo instances across your infrastructure and verifying their current configuration status regarding the 'SOGoTrustProxyAuthentication' parameter. If the setting is enabled, consult your administrative documentation to plan an update to version 5.8.0~ynh9 or later, which contains the necessary fix. Coordinate with your infrastructure teams to confirm the software version and restrict external access until the update is successfully applied.

References