AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-74864.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.3CVSS 4.0 · cvd@cert.pl
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSDeferredModified Sep 30, 2026

Disclosure summary

sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Nginx does not strip this header, any client can supply it arbitrarily and gain access as any user, including a privileged user, without providing a password. This issue was fixed in version 5.8.0~ynh9.

Source-reported weakness categories

CWE-639

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-74864

Open original source · Updated Sep 30, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-09-30T09:17:19-04:00
MODIFIED 2026-09-30T15:57:08-04:00
INGESTED 2026-10-06T11:44:58-04:00