Skip to content
USN-8504-1: SOGo vulnerabilities

USN-8504-1: SOGo vulnerabilities

Ubuntu July 5, 2026

It was discovered that SOGo did not properly sanitize categories used for events, tasks, and contacts. A remote authenticated attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. ( CVE-2025-71276 ) It was discovered that SOGo did not properly sanitize the hint query parameter. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-3054 ) It was discovered that SOGo did not renew the one-time password when a user disabled and re-enabled it, and used a shorter length than recommended. A remote attacker could possibly use this issue to bypass authentication. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (

It was discovered that SOGo did not properly sanitize categories used for events, tasks, and contacts. A remote authenticated attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. ( CVE-2025-71276 )

It was discovered that SOGo did not properly sanitize the hint query parameter. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-3054 )

It was discovered that SOGo did not renew the one-time password when a user disabled and re-enabled it, and used a shorter length than recommended. A remote attacker could possibly use this issue to bypass authentication. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (

It was discovered that SOGo did not properly sanitize categories used for events, tasks, and contacts. A remote authenticated attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. ( CVE-2025-71276 ) It was discovered that SOGo did not properly sanitize the hint query parameter. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-3054 ) It was discovered that SOGo did not renew the one-time password when a user disabled and re-enabled it, and used a shorter length than recommended. A remote attacker could possibly use this issue to bypass authentication. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. ( CVE-2026-33550 ) It was discovered that SOGo did not properly use the SQL adaptor for the user source, resulting in SQL injection when certain databases were used. A remote authenticated attacker could possibly use this issue to obtain sensitive information or execute arbitrary SQL commands. ( CVE-2026-46445 , CVE-2026-46446 ) It was discovered that SOGo did not properly sanitize mail containing ICS calendar invitations. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-8496 ) It was discovered that SOGo did not properly validate identifiers when managing access control lists. A remote authenticated attacker could possibly use this issue to perform SQL injection attacks and obtain sensitive information. ( CVE-2026-8851 ) It was discovered that SOGo did not properly sanitize the theme parameter. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. ( CVE-2025-63499 ) It was discovered that SOGo did not properly sanitize the userName parameter on the login page. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. ( CVE-2025-63498 ) It was discovered that SOGo did not properly sanitize attachments when previewing them. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. ( CVE-2024-34462 ) It was discovered that SOGo did not validate the signatures of SAML assertions it received when SAML was used for authentication. A remote attacker could possibly use this issue to impersonate other users. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. ( CVE-2021-33054 )

It was discovered that SOGo did not properly sanitize categories used for events, tasks, and contacts. A remote authenticated attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. ( CVE-2025-71276 )

It was discovered that SOGo did not properly sanitize the hint query parameter. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-3054 )

It was discovered that SOGo did not renew the one-time password when a user disabled and re-enabled it, and used a shorter length than recommended. A remote attacker could possibly use this issue to bypass authentication. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. ( CVE-2026-33550 )

It was discovered that SOGo did not properly use the SQL adaptor for the user source, resulting in SQL injection when certain databases were used. A remote authenticated attacker could possibly use this issue to obtain sensitive information or execute arbitrary SQL commands. ( CVE-2026-46445 , CVE-2026-46446 )

It was discovered that SOGo did not properly sanitize mail containing ICS calendar invitations. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 26.04 LTS. ( CVE-2026-8496 )

It was discovered that SOGo did not properly validate identifiers when managing access control lists. A remote authenticated attacker could possibly use this issue to perform SQL injection attacks and obtain sensitive information. ( CVE-2026-8851 )

It was discovered that SOGo did not properly sanitize the theme parameter. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. ( CVE-2025-63499 )

It was discovered that SOGo did not properly sanitize the userName parameter on the login page. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. ( CVE-2025-63498 )

It was discovered that SOGo did not properly sanitize attachments when previewing them. A remote attacker could possibly use this issue to perform cross-site scripting attacks. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. ( CVE-2024-34462 )

It was discovered that SOGo did not validate the signatures of SAML assertions it received when SAML was used for authentication. A remote attacker could possibly use this issue to impersonate other users. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. ( CVE-2021-33054 )

After a standard system update you need to restart SOGo to make all the necessary changes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.