CVE-2026-74865: CWE-639 Authorization bypass through User-Controlled key in YunoHost-Apps sogo_yhn
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.
AI Analysis
Technical Summary
The vulnerability CVE-2026-74865 in YunoHost-Apps sogo_yhn is due to the configuration parameter "SOGoTrustProxyAuthentication=YES". This setting causes the HTTP Basic authentication mechanism to skip password validation, allowing an attacker to authenticate as any user by providing only the username and an arbitrary password. This effectively bypasses authentication controls and grants unauthorized access to user accounts. The issue was addressed and fixed in version 5.8.0~ynh9.
Potential Impact
An unauthenticated attacker can bypass password authentication and gain unauthorized access to any existing user's account in sogo_yhn versions prior to 5.8.0~ynh9. This compromises user account confidentiality and integrity, potentially allowing full access to user data and actions within the application.
Mitigation Recommendations
Upgrade sogo_yhn to version 5.8.0~ynh9 or later, where this vulnerability has been fixed. No other mitigation is required as the issue is resolved in the official patch.
CVE-2026-74865: CWE-639 Authorization bypass through User-Controlled key in YunoHost-Apps sogo_yhn
Description
sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the username of an existing user and any arbitrary password can successfully log in to that user's account. This issue was fixed in version 5.8.0~ynh9.
CVSS v4.0
Score 9.2critical
Affected software
YunoHost-Apps
sogo_yhn
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-74865 in YunoHost-Apps sogo_yhn is due to the configuration parameter "SOGoTrustProxyAuthentication=YES". This setting causes the HTTP Basic authentication mechanism to skip password validation, allowing an attacker to authenticate as any user by providing only the username and an arbitrary password. This effectively bypasses authentication controls and grants unauthorized access to user accounts. The issue was addressed and fixed in version 5.8.0~ynh9.
Potential Impact
An unauthenticated attacker can bypass password authentication and gain unauthorized access to any existing user's account in sogo_yhn versions prior to 5.8.0~ynh9. This compromises user account confidentiality and integrity, potentially allowing full access to user data and actions within the application.
Mitigation Recommendations
Upgrade sogo_yhn to version 5.8.0~ynh9 or later, where this vulnerability has been fixed. No other mitigation is required as the issue is resolved in the official patch.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-08-17T10:19:51.723Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abd07622a4e24523d03fb29
Added to database: 09/30/2026, 12:58:10 UTC
Last enriched: 09/30/2026, 13:02:55 UTC
Last updated: 10/01/2026, 02:51:47 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.