CVE-2026-39179

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.

Published 2026-07-08. Last modified 2026-07-09.