CVE-2026-8496 Details
Description
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS file, with an onrepeat event handler, is insufficiently sanitized before being rendered in the webmail interface. A remote attacker can execute JavaScript in the victim's browser when the malicious calendar invite is viewed. Successful exploitation may allow mailbox access, email and contact theft, session hijacking, and other actions allowed by an authenticated user.
A cross-site scripting (XSS) vulnerability has been identified in Alinto SOGo version 5.12.7. This issue allows for arbitrary JavaScript execution within an authenticated SOGo webmail session. The vulnerability arises from insufficient sanitization of SVG content embedded in the description field of ICS calendar invitation files. When such a malicious invitation is viewed, the JavaScript executes in the victim's browser. Successful exploitation could lead to unauthorized access to the mailbox, theft of emails and contacts, session hijacking, and other actions permitted by an authenticated user.
Users are advised to update to SOGo version 5.12.8, which addresses this vulnerability. The update is available on the Alinto SOGo GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2026CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/487613 | CVE | |
| https://github.com/Alinto/sogo/commit/67ce01ec2a1a7854d8e9f615dd65afb949043e86 | [email protected] | Source CodeVendor |
| https://github.com/Alinto/sogo/releases/tag/SOGo-5.12.8 | [email protected] | Release NotesVendor |
| https://www.sogo.nu/news/2026/sogo-v5128-released.html | [email protected] | Release NotesVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Alinto SOGo | < 5.12.8 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CVE |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |
| May 13, 2026 | CVE Modified | CISA-ADP |
Volerion