DEBIAN-CVE-2026-8851

Source
https://security-tracker.debian.org/tracker/CVE-2026-8851
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-8851.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-8851
Upstream
Published
2026-05-18T21:16:41Z
Modified
2026-09-01T16:07:07Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL code to write extracted data into the sogo_acl table and retrieve it through the /acls API, establishing an out-of-band data exfiltration channel.

References

Affected packages

Debian:12 / sogo

Package

Name
sogo
Purl
pkg:deb/debian/sogo?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.8.0-2+deb12u3

Affected versions

5.*
5.8.0-1
5.8.0-2+deb12u1
5.8.0-2+deb12u2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-8851.json"

Debian:13 / sogo

Package

Name
sogo
Purl
pkg:deb/debian/sogo?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.12.1-3+deb13u2

Affected versions

5.*
5.12.1-3
5.12.1-3+deb13u1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-8851.json"