PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46445 Mail Archive CVE debrief

CVE-2026-46445 is a SQL injection issue in SOGo before 5.12.7 when PostgreSQL is used. The supplied advisory metadata rates it CVSS 7.1 (High) with network reachability, low privileges, and no user interaction, so affected PostgreSQL-backed deployments should be patched promptly.

Vendor
Mail Archive
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-05-14
Advisory published
2026-05-14
Advisory updated
2026-05-14

Who should care

SOGo administrators, mail/groupware operators, database and application security teams, and anyone running SOGo with PostgreSQL in production or internet-facing environments.

Technical summary

The GitHub Advisory Database entry for CVE-2026-46445 identifies CWE-89 (SQL Injection) in SOGo versions before 5.12.7, specifically when PostgreSQL is the backend. The advisory metadata lists CVSS v3.1 AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L, indicating remote exposure with low privileges and potentially significant confidentiality and integrity impact.

Defensive priority

High priority for any SOGo deployment using PostgreSQL; upgrade as soon as possible and verify exposure across all instances.

Recommended defensive actions

  • Upgrade SOGo to version 5.12.7 or later on all affected deployments.
  • Confirm whether each SOGo instance uses PostgreSQL; prioritize patching any PostgreSQL-backed installation.
  • Review application and database logs for unusual or unexpected SQL activity around the exposure window.
  • If suspicious activity is found, treat the instance as potentially impacted and assess data confidentiality and integrity.

Evidence notes

Primary evidence comes from the GitHub Advisory Database entry GHSA-vhv6-3crj-r8jm and the linked official SOGo 5.12.7 release notice. The advisory metadata explicitly lists CVE-2026-46445, CWE-89, and CVSS v3.1 AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L. NVD also lists the CVE, and the supplied source item is marked unreviewed, so the linked SOGo references are important for corroboration of the affected version and fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46445 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46445

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46445 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46445

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://github.com/advisories/GHSA-vhv6-3crj-r8jm

    github_advisory_database

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Alinto/sogo/pull/379/changes/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg2100131.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.sogo.nu/news/2026/sogo-v5127-released.html

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.