CVE-2026-33550: Alinto Sogo

Low severity, CVSS 2.6. EPSS: 0.2% chance of exploitation in the next 30 days.

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).

Affected products

  • Alinto Sogo: before 5.12.5 (fixed in 5.12.5)

Published 2026-03-22. Last modified 2026-06-17.