CVE-2026-33550: Alinto Sogo
Low severity, CVSS 2.6. EPSS: 0.2% chance of exploitation in the next 30 days.
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).
Affected products
- Alinto Sogo: before 5.12.5 (fixed in 5.12.5)
Published 2026-03-22. Last modified 2026-06-17.