VORANT. Threat Intelligence Sign in Get the full feed

SOGo webmail XSS-to-RCE flaw exploited in wild

high vulnerability

An actively exploited XSS bug in Alinto SOGo lets attackers hijack mailboxes via malicious SVG payloads embedded in calendar invites.

CERT/CC disclosed CVE-2026-8496, a cross-site scripting vulnerability in Alinto SOGo v5.12.7 that stems from insufficient sanitization of the DESCRIPTION field in ICS calendar invitations. Attackers can embed SVG objects containing JavaScript event handlers (e.g., <animate onrepeat='...'>) that execute automatically when a victim views or previews the calendar tab in SOGo's webmail interface, requiring no further interaction beyond opening the calendar view.

Successful exploitation grants the attacker full read access to the victim's mailbox, enabling credential theft via forced logout/login phishing, password manager autofill hijacking, and exfiltration of emails, contacts, and calendar metadata. VirusTotal sightings confirm this vulnerability has already been exploited in the wild, making it an active threat to any organization running vulnerable SOGo instances rather than a theoretical risk. SOGo is commonly deployed by organizations as a self-hosted groupware layer atop existing mail infrastructure, meaning exposure spans a broad range of self-hosting enterprises.

The vendor has patched the issue in SOGo v5.12.8, which sanitizes ICS DESCRIPTION content and enforces stricter handling of embedded SVG and HTML. Organizations running SOGo should prioritize upgrading given confirmed real-world exploitation and the low interaction bar (a mere calendar preview) required to trigger the payload.

Mentioned in this report

Vulnerabilities CVE-2026-8496

Source reporting: https://kb.cert.org/vuls/id/487613

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free