Security Advisory

CVE-2026-39178

6.3
MEDIUM

Vulnerability Description

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.
Published Date July 8, 2026
Official Source NIST NVD Advisory