SOGo SQL Injection Vulnerability in PostgreSQL User Sources

Vulnerability

A SQL injection vulnerability has been identified in SOGo versions prior to 5.12.7, specifically when PostgreSQL is used as the database. This vulnerability arises from improper handling of user credentials, allowing for malicious SQL queries to be executed.

Impact

Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries and potentially access or modify sensitive data.

Remediation

Users are advised to update to SOGo version 5.12.7 or later. Instructions for updating can be found in the SOGo release notes.

Added: May 14, 2026, 4:21 AM
Updated: May 14, 2026, 4:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
8.4
remediation
7.7
relevance
8.3
threat
3.2
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.