A vulnerability described as problematic has been identified in Alinto SOGo up to 5.12.7. Affected by this vulnerability is an unknown functionality of the component Webmail Interface. Such manipulation of the argument Description leads to cross site scripting. This vulnerability is traded as CVE-2026-8496. The attack may be launched remotely.
| Vendor | Product | Versions |
|---|---|---|
| alinto sogo | sogo | 0, 5.12.7 |
Updated vendor to Alinto, product to SOGo, severity to HIGH, added CWE-79, and clarified that the vulnerability is CVE-2026-8496.
Initial creation