CVE-2026-46446 UNKNOWN

CVE-2026-46446

Published: 2026-05-14

Description

SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…