A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. (CVE-2026-8496)
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo version 5.12.7. This flaw allows arbitrary JavaScript execution within an authenticated user's webmail session when viewing a maliciously crafted ICS calendar invitation containing SVG content with an onrepeat event handler. Exploitation could lead to mailbox access, theft of emails and contacts, session hijacking, and other actions permitted to the authenticated user.
AI Analysis
Technical Summary
CVE-2026-8496 is a cross-site scripting vulnerability in Alinto SOGo version 5.12.7. The vulnerability arises from insufficient sanitization of SVG content embedded in the description field of ICS calendar invitation files, specifically when an onrepeat event handler is present. When a victim views such a malicious calendar invite in their authenticated SOGo webmail session, arbitrary JavaScript can execute in their browser. This enables an attacker to perform actions such as accessing mailbox contents, stealing emails and contacts, and hijacking the user session.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary JavaScript in the context of an authenticated user's webmail session. This can lead to unauthorized mailbox access, theft of sensitive information including emails and contacts, session hijacking, and potentially other actions available to the authenticated user. The vulnerability requires user interaction (viewing the malicious calendar invite) and does not require prior privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should exercise caution when opening ICS calendar invitations from untrusted sources. Monitoring vendor channels for updates is recommended.
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. (CVE-2026-8496)
Description
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo version 5.12.7. This flaw allows arbitrary JavaScript execution within an authenticated user's webmail session when viewing a maliciously crafted ICS calendar invitation containing SVG content with an onrepeat event handler. Exploitation could lead to mailbox access, theft of emails and contacts, session hijacking, and other actions permitted to the authenticated user.
CVSS v3.1
Score 6.1medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-8496 is a cross-site scripting vulnerability in Alinto SOGo version 5.12.7. The vulnerability arises from insufficient sanitization of SVG content embedded in the description field of ICS calendar invitation files, specifically when an onrepeat event handler is present. When a victim views such a malicious calendar invite in their authenticated SOGo webmail session, arbitrary JavaScript can execute in their browser. This enables an attacker to perform actions such as accessing mailbox contents, stealing emails and contacts, and hijacking the user session.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary JavaScript in the context of an authenticated user's webmail session. This can lead to unauthorized mailbox access, theft of sensitive information including emails and contacts, session hijacking, and potentially other actions available to the authenticated user. The vulnerability requires user interaction (viewing the malicious calendar invite) and does not require prior privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should exercise caution when opening ICS calendar invitations from untrusted sources. Monitoring vendor channels for updates is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5wp7-63mq-392x
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-8496"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7573b5bf8831d539d939e3
Added to database: 08/07/2026, 05:57:09 UTC
Last enriched: 08/07/2026, 08:02:26 UTC
Last updated: 08/08/2026, 00:41:15 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.