CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)

CVE-2026-74864 / CVE-2026-74865 (TL-2026-2816) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-09-30. It has no confirmed attribution, affects YunoHost-Apps sogo_yhn (sogo_ynh SOGo package for YunoHost), references 2 CVEs (CVE-2026-74864, CVE-2026-74865), maps to 5 MITRE ATT&CK techniques (T1078, T1114, T1190), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2816

Threat ID
TL-2026-2816
Severity
CRITICAL
CVSS
9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, education, non-profit organisation
Target regions
Global
Detection rules
9
Indicators of compromise
10

Malware and tooling in CVE-2026-74864 / CVE-2026-74865

Malware and tooling: CALENDAR - S0025

Two CWE-639 authentication-bypass flaws in the YunoHost-Apps sogo_yhn package (SOGo groupware for YunoHost) let an unauthenticated network attacker log in as any existing user, including administrators, either by sending a forged x-webobjects-remote-user header or by supplying any password over HTTP Basic auth. All versions before 5.8.0~ynh9 are affected; NVD scores them CVSS 4.0 9.3 and 9.2 (CRITICAL).

How CVE-2026-74864 / CVE-2026-74865 works

CERT Polska (published 2026-09-30, credit Przemysław Knycz / WeKrwi.IT) disclosed two authorization-bypass vulnerabilities (CWE-639, Authorization Bypass Through User-Controlled Key) in sogo_yhn, the YunoHost-Apps (sogo_ynh) package that deploys the SOGo groupware (mail, calendars, address books) on YunoHost self-hosted servers.

CVE-2026-74864: the package configures SOGo so that a request carrying the HTTP header x-webobjects-remote-user is treated as sent by a verified user, with no password validation. Because the Nginx front end does not strip this header from client requests, a remote attacker can supply it directly and access any account, including administrative accounts, without authenticating. NVD scores this CVSS 4.0 9.3 CRITICAL (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H).

CVE-2026-74865: the package enables SOGo with SOGoTrustProxyAuthentication=YES, which bypasses password verification during HTTP Basic authentication. An unauthenticated attacker who knows the username of an existing user can log in with any arbitrary password. NVD scores this CVSS 4.0 9.2 CRITICAL (AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H).

Background: SOGo's own documentation states SOGoTrustProxyAuthentication defaults to NO and warns that enabling it lets a misconfigured proxy or network weakness allow user impersonation through injected authentication headers; the setting should only be used where the proxy layer is fully controlled. In the YunoHost package the untrusted client-facing Nginx did not remove the trusted header, which is the root cause. The package's public nginx.conf proxies to 127.0.0.1 and sets other x-webobjects-* headers (server-protocol, remote-host, server-name, server-url, server-port) itself.

The YunoHost forum announced a critical SOGo package fix on 2026-07-29 with technical details embargoed for roughly one month; the fix is SOGo package 5.8.0~ynh9, which requires YunoHost >= 12.1.38 (YunoHost 11 users must upgrade YunoHost first). SSO integration is disabled until migration to SOGo 6. Users who could not upgrade at once were given temporary manual configuration workarounds. No in-the-wild exploitation, public PoC, or network IOCs are stated in any source; CERT Polska gives no CVSS, but NVD lists CVSS 4.0 scores for both CVEs. Impact is full read/write access to a victim mailbox, calendar and contacts, and possibly SOGo administrative functions.

MITRE ATT&CK techniques used in TL-2026-2816

Privilege Escalation

T1078 Valid Accounts

Collection

T1114 Email Collection; T1213 Data from Information Repositories

Initial Access

T1190 Exploit Public-Facing Application

lateral-movement

T1550 Use Alternate Authentication Material

Affected products and versions in CVE-2026-74864 / CVE-2026-74865

  • YunoHost-Apps — sogo_yhn (sogo_ynh SOGo package for YunoHost)
    Vulnerable versions: all versions before 5.8.0~ynh9
    Fixed in: 5.8.0~ynh9

Remediation for CVE-2026-74864 / CVE-2026-74865

Patches

  • YunoHost-Apps sogo_ynh 5.8.0~ynh9 (requires YunoHost >= 12.1.38)

Immediate actions

  • Upgrade the YunoHost SOGo package (sogo_ynh) to 5.8.0~ynh9 or later and restart the server after the update
  • If YunoHost is v11, first upgrade YunoHost to >= 12.1.38, which the fixed package requires
  • If patching is delayed, apply the temporary manual configuration workaround from the YunoHost forum notice
  • Hunt web/Nginx logs for external requests carrying an x-webobjects-remote-user header and for SOGo Basic-auth logins that succeeded with a wrong password (analyst recommendation)

Workarounds

  • Temporary manual configuration workaround published in the YunoHost forum announcement; SSO is disabled until migration to SOGo 6

Longer-term hardening

  • Ensure any reverse proxy strips client-supplied x-webobjects-* authentication headers before forwarding to SOGo
  • Keep SOGoTrustProxyAuthentication at its default NO unless the proxy layer is fully controlled
  • Review mailboxes, forwarding rules and calendar/contact access for accounts that may have been accessed unauthenticated (analyst recommendation)

CVEs associated with CVE-2026-74864 / CVE-2026-74865

CVE-2026-74864, CVE-2026-74865

Weaknesses (CWE) in CVE-2026-74864 / CVE-2026-74865

CWE-639

Timeline of CVE-2026-74864 / CVE-2026-74865

  • Fixed package sogo_ynh 5.8.0~ynh9 available (requires YunoHost >= 12.1.38); SSO disabled until migration to SOGo 6; temporary manual workarounds offered
  • YunoHost forum announces a critical SOGo package vulnerability, urging upgrade to 5.8.0~ynh9; technical details withheld under an embargo planned for about one month
  • Approximate end of the one-month disclosure embargo planned in the forum notice (planned date, not a confirmed publication)
  • CVE-2026-74865 published with CVSS 4.0 base score 9.2 CRITICAL: SOGoTrustProxyAuthentication=YES lets any password pass HTTP Basic auth for an existing username
  • CVE-2026-74864 published with CVSS 4.0 base score 9.3 CRITICAL: forged x-webobjects-remote-user header accepted as a verified user
  • CERT Polska publishes the advisory for CVE-2026-74864 and CVE-2026-74865 (CWE-639), crediting Przemysław Knycz of WeKrwi.IT

Sources cited for CVE-2026-74864 / CVE-2026-74865

More in vulnerability

Detection coverage for TL-2026-2816

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2816 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats