VDB
CVE-2026-8851
CVE-2026-8851
PUBLISHED
CVSS 8.600000381469727 HIGH
SOGo 5.12.7 contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL code to write extracted data into the sogo_acl table and retrieve it through the /acls API, establishing an out-of-band data exfiltration channel.
EPSS 0.32% · 24.7th percentile
Risk Scores
CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.32%
24.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alinto | SOGo Webmail | 5.12.8, 5.12.7 |
Timeline
- May 18, 2026 CVE Published
- May 19, 2026 EPSS Score
- May 19, 2026 Coalition ESS Score
- May 19, 2026 Security Advisory
- May 19, 2026 CVE Updated
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score