SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-640"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93453.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93453.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"225942381120307779212702195603196938395",
"78201249962957314865711573196513007782",
"99580188145299495242851591184750488134",
"263398982896022421337082381569175600772"
],
"threshold": 0.9
},
"id": "CVE-2026-93453-83a426eb",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/alinto/sogo/commit/04a3e9823889acaf6c247b224f5f7a0108f8f829",
"target": {
"file": "SoObjects/SOGo/SOGoSystemDefaults.h"
}
}
]
"2026-09-19T08:03:45Z"