CVE-2026-93453: Weak Password Recovery Mechanism for Forgotten Password in Alinto SOGo
CVE-2026-93453 is a vulnerability in Alinto SOGo versions before 5.12.11 where password-reset links are constructed using the client-supplied Origin header. This flaw allows unauthenticated attackers to craft password recovery requests with malicious Origin headers, causing valid password-reset tokens to be sent in links pointing to attacker-controlled domains. This can lead to account takeover if victims use these malicious links.
AI Analysis
Technical Summary
Alinto SOGo versions prior to 5.12.11 have a weakness in their password recovery mechanism. The application uses the Origin header supplied by the client to build password-reset URLs without proper validation. An attacker can exploit this by submitting password recovery requests with a malicious Origin header, resulting in password-reset emails containing links that redirect to attacker-controlled domains. This enables attackers to intercept recovery tokens and potentially take over user accounts.
Potential Impact
The vulnerability allows unauthenticated attackers to redirect password-reset tokens to domains they control, facilitating account takeover of affected users. This compromises user account security and may lead to unauthorized access.
Mitigation Recommendations
A fix is available in Alinto SOGo version 5.12.11. Users should upgrade to version 5.12.11 or later to remediate this vulnerability. No other mitigation guidance is provided.
CVE-2026-93453: Weak Password Recovery Mechanism for Forgotten Password in Alinto SOGo
Description
CVE-2026-93453 is a vulnerability in Alinto SOGo versions before 5.12.11 where password-reset links are constructed using the client-supplied Origin header. This flaw allows unauthenticated attackers to craft password recovery requests with malicious Origin headers, causing valid password-reset tokens to be sent in links pointing to attacker-controlled domains. This can lead to account takeover if victims use these malicious links.
CVSS v4.0
Score 8.7high
Affected software
Alinto
SOGo
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Alinto SOGo versions prior to 5.12.11 have a weakness in their password recovery mechanism. The application uses the Origin header supplied by the client to build password-reset URLs without proper validation. An attacker can exploit this by submitting password recovery requests with a malicious Origin header, resulting in password-reset emails containing links that redirect to attacker-controlled domains. This enables attackers to intercept recovery tokens and potentially take over user accounts.
Potential Impact
The vulnerability allows unauthenticated attackers to redirect password-reset tokens to domains they control, facilitating account takeover of affected users. This compromises user account security and may lead to unauthorized access.
Mitigation Recommendations
A fix is available in Alinto SOGo version 5.12.11. Users should upgrade to version 5.12.11 or later to remediate this vulnerability. No other mitigation guidance is provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-17T22:45:31.286Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aac788555bf5e2cf5129616
Added to database: 09/17/2026, 23:32:21 UTC
Last enriched: 09/17/2026, 23:46:32 UTC
Last updated: 09/18/2026, 00:23:29 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.