# SOGo webmail XSS-to-RCE flaw exploited in wild

Published: 2026-08-06 · Severity: high
Canonical: https://vorant.io/reports/1975e281-d139-5dde-aed0-155a4a22d78e/sogo-webmail-xss-to-rce-flaw-exploited-in-wild

> An actively exploited XSS bug in Alinto SOGo lets attackers hijack mailboxes via malicious SVG payloads embedded in calendar invites.

CERT/CC disclosed CVE-2026-8496, a cross-site scripting vulnerability in Alinto SOGo v5.12.7 that stems from insufficient sanitization of the DESCRIPTION field in ICS calendar invitations. Attackers can embed SVG objects containing JavaScript event handlers (e.g., <animate onrepeat='...'>) that execute automatically when a victim views or previews the calendar tab in SOGo's webmail interface, requiring no further interaction beyond opening the calendar view.

Successful exploitation grants the attacker full read access to the victim's mailbox, enabling credential theft via forced logout/login phishing, password manager autofill hijacking, and exfiltration of emails, contacts, and calendar metadata. VirusTotal sightings confirm this vulnerability has already been exploited in the wild, making it an active threat to any organization running vulnerable SOGo instances rather than a theoretical risk. SOGo is commonly deployed by organizations as a self-hosted groupware layer atop existing mail infrastructure, meaning exposure spans a broad range of self-hosting enterprises.

The vendor has patched the issue in SOGo v5.12.8, which sanitizes ICS DESCRIPTION content and enforces stricter handling of embedded SVG and HTML. Organizations running SOGo should prioritize upgrading given confirmed real-world exploitation and the low interaction bar (a mere calendar preview) required to trigger the payload.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8496

Source reporting: https://kb.cert.org/vuls/id/487613

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1975e281-d139-5dde-aed0-155a4a22d78e/sogo-webmail-xss-to-rce-flaw-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
