PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46446 Mail Archive CVE debrief

CVE-2026-46446 is a HIGH-severity SQL injection issue affecting SOGo before 5.12.7 in deployments that use PostgreSQL or MariaDB and store passwords in cleartext. The advisory ties the flaw to the changePasswordForLogin path and the c_password = '%@' SQL construction pattern. The supplied sources indicate a public fix was released in SOGo 5.12.7, with the advisory published on 2026-05-14. The GitHub advisory is marked unreviewed, so defenders should rely on the upstream release note and fix references when validating remediation.

Vendor
Mail Archive
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-05-14
Advisory published
2026-05-14
Advisory updated
2026-05-14

Who should care

SOGo administrators and operators, especially those using PostgreSQL or MariaDB and any environment that stores passwords in cleartext. Security teams responsible for authentication flows and database-backed password management should prioritize review.

Technical summary

The issue is an SQL injection in the password-change flow. According to the advisory text, the risky code path is changePasswordForLogin, where c_password = '%@' is called out as related to the vulnerability. The reported impact is reflected in the supplied CVSS vector: network reachable, no user interaction, low privileges, and potential high impact to confidentiality and integrity with limited availability impact.

Defensive priority

High. Upgrade affected SOGo deployments to 5.12.7 or later as soon as practical, then verify whether the environment uses PostgreSQL or MariaDB and whether cleartext passwords are stored. If exposure is possible, treat the environment as priority review and validate for abnormal authentication or database activity.

Recommended defensive actions

  • Upgrade SOGo to version 5.12.7 or later.
  • Confirm whether the affected deployment uses PostgreSQL or MariaDB.
  • Verify whether passwords are stored in cleartext and plan to eliminate that configuration.
  • Review the upstream release note and fix reference to confirm the applied patch.
  • Inspect authentication and database activity for signs of unexpected password-change or SQL execution behavior.
  • Rotate credentials and investigate further if you suspect the vulnerable path was abused.

Evidence notes

The supplied sources identify the issue as CVE-2026-46446 / GHSA-37h6-wqp6-qg5g, with CVSS 3.1 vector AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L and score 7.1. Publication timing in the provided corpus is 2026-05-14T06:31:32Z for the advisory/CVE record, with an NVD publication timestamp of 2026-05-14T04:17:03Z. Supporting references include the upstream SOGo 5.12.7 release note, an upstream pull request diff, and a Debian bug thread. No KEV entry was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46446 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46446

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46446 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46446

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://github.com/advisories/GHSA-37h6-wqp6-qg5g

    github_advisory_database

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Alinto/sogo/pull/379/changes/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg2100131.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.sogo.nu/news/2026/sogo-v5127-released.html

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.