CVE-2026-39179
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.
Published 2026-07-08. Last modified 2026-07-09.