Medium severity6.3OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-39178
CVE-2026-39178
Description
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.
Affected products
3Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.