CVE-2026-39178

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.

Published 2026-07-08. Last modified 2026-07-09.