Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-8851

Опубликовано: 18 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 8.1

Описание

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL code to write extracted data into the sogo_acl table and retrieve it through the /acls API, establishing an out-of-band data exfiltration channel.

РелизСтатусПримечание
devel

not-affected

5.12.9-1
esm-apps-legacy/xenial

released

2.2.17a-1.1ubuntu0.1~esm1
esm-apps/bionic

released

3.2.10-1ubuntu0.1~esm1
esm-apps/focal

released

4.3.0-1ubuntu0.1~esm1
esm-apps/jammy

released

5.5.1-1ubuntu0.1~esm1
esm-apps/resolute

released

5.12.4-1.2ubuntu0.1~esm1
jammy

needed

noble

DNE

questing

ignored

end of life, was needed
resolute

needed

Показывать по

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
3 месяца назад

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL code to write extracted data into the sogo_acl table and retrieve it through the /acls API, establishing an out-of-band data exfiltration channel.

CVSS3: 8.1
debian
3 месяца назад

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability ...

CVSS3: 8.1
github
3 месяца назад

SOGo 5.12.7 contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL subqueries through the uid parameter of the addUserInAcls endpoint. Attackers can inject malicious SQL code to write extracted data into the sogo_acl table and retrieve it through the /acls API, establishing an out-of-band data exfiltration channel.

8.1 High

CVSS3

Уязвимость CVE-2026-8851