VDB

CVE-2026-3054

CVE-2026-3054 PUBLISHED CVSS 5.300000190734863 MEDIUM

A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS 0.40% · 33.8th percentile

Risk Scores

CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
EPSS Score
0.40%
33.8th percentile

Affected Products

VendorProductVersions
AlintoSOGo5.12.4, 5.12.3, 5.12.4
alintosogo5.12.3, 5.12.3, 5.12.4

Timeline

  • Feb 23, 2026 CVE ID Reserved
  • Feb 24, 2026 EPSS Score
  • Feb 24, 2026 CVE Published
  • Feb 24, 2026 PoC Published
  • Feb 24, 2026 CVE Updated
  • Feb 26, 2026 EPSS Score
  • Feb 28, 2026 EPSS Score
  • Mar 2, 2026 EPSS Score
  • Mar 3, 2026 EPSS Score
  • Mar 5, 2026 EPSS Score
  • Mar 7, 2026 EPSS Score
  • Mar 9, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›