SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
{
"cna_assigner": "mitre",
"cwe_ids": [
"CWE-308"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33550.json"
}{
"cpe": "cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "5.12.5"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33550.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"210430912351680258099012889449626424136",
"118547479593593158927144485846800927963",
"52033065985110991692933028964535079607",
"78940714658635439390355102182641246101"
],
"threshold": 0.9
},
"id": "CVE-2026-33550-8d4b411e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2",
"target": {
"file": "SoObjects/SOGo/SOGoUser.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"177686447049141624995183196277635006705",
"89741928345062303720684782183649812723",
"132955516672192288287528512238777328059",
"174630184015155944436707833403087040168"
],
"threshold": 0.9
},
"id": "CVE-2026-33550-c755e580",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2",
"target": {
"file": "SoObjects/SOGo/SOGoUserSettings.h"
}
}
]
"2026-08-12T15:33:25Z"