Full Report
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-74864 and CVE-2026-74865) found in YunoHost-Apps sogo_yhn software.
Analysis Summary
# Vulnerability: Authentication Bypass in YunoHost-Apps sogo_yhn
## CVE Details
- **CVE ID**: CVE-2026-74864, CVE-2026-74865
- **CVSS Score**: Not explicitly provided in the report, but estimated as **9.8 (Critical)** based on technical details (unauthenticated remote administrative access).
- **CWE**: CWE-639 (Authorization Bypass Through User-Controlled Key)
## Affected Systems
- **Products**: YunoHost-Apps sogo_yhn (SOGo integration for YunoHost)
- **Versions**: All versions prior to **5.8.0~ynh9**
- **Configurations**: Default configurations where SOGo is integrated via the `sogo_yhn` package.
## Vulnerability Description
The software suffers from two critical flaws in how it handles authentication proxies:
1. **CVE-2026-74864 (Header Injection Bypass):** The application is configured to trust the `x-webobjects-remote-user` HTTP header to identify verified users without password validation. Because the Nginx reverse proxy was not configured to strip this header from incoming external requests, an attacker can supply this header to impersonate any user, including administrators.
2. **CVE-2026-74865 (Proxy Authentication Bypass):** The application uses the parameter `SOGoTrustProxyAuthentication=YES`. This configuration causes the system to bypass password verification during HTTP Basic authentication. An attacker only needs a valid username and any arbitrary string as a password to gain full access to an account.
## Exploitation
- **Status**: Not currently reported as exploited in the wild (Reported via CVD); PoC details are implied by the vulnerability description.
- **Complexity**: Low
- **Attack Vector**: Network
## Impact
- **Confidentiality**: High (Access to all user emails, calendars, and data)
- **Integrity**: High (Ability to modify user data or settings)
- **Availability**: High (Potential for account lockout or administrative takeover)
## Remediation
### Patches
- **Upgrade to version 5.8.0~ynh9 or later.** This version updates the Nginx configuration and SOGo parameters to ensure authentication is properly enforced.
### Workarounds
- Manually configure the Nginx frontend to strip the `x-webobjects-remote-user` header from all incoming client requests.
- Set `SOGoTrustProxyAuthentication` to `NO` in the SOGo configuration file if proxy-based authentication is not strictly required by the environment.
## Detection
- **Indicators of Compromise**: Review Nginx/SOGo access logs for unusual logins where the `x-webobjects-remote-user` header is present in requests originating from external IP addresses.
- **Detection methods**: Security scanners can be used to attempt a login with a known valid username and an incorrect password to see if the "TrustProxyAuthentication" flaw is active.
## References
- CERT Polska Advisory: [https://cert.pl/en/posts/2026/09/cvd-2026-74864-74865/](https://cert.pl/en/posts/2026/09/cvd-2026-74864-74865/) (Defanged: hxxps[://]cert[.]pl/en/posts/2026/09/cvd-2026-74864-74865/)
- CVE-2026-74864: [https://www.cve.org/CVERecord?id=CVE-2026-74864](https://www.cve.org/CVERecord?id=CVE-2026-74864) (Defanged: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-74864)
- CVE-2026-74865: [https://www.cve.org/CVERecord?id=CVE-2026-74865](https://www.cve.org/CVERecord?id=CVE-2026-74865) (Defanged: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-74865)