Home

Description

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).

PUBLISHED Reserved 2026-03-22 | Published 2026-03-22 | Updated 2026-03-23 | Assigner mitre




LOW: 2.0CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N

Problem types

CWE-308 Use of Single-factor Authentication

Product status

Default status
unaffected

Any version before 5.12.5
affected

References

github.com/...ommit/83d4c522f87cfde0ba543837d9b24c3479083ec2

github.com/Alinto/sogo/releases/tag/SOGo-5.12.5

cve.org (CVE-2026-33550)

nvd.nist.gov (CVE-2026-33550)

Download JSON