Security Advisory

CVE-2026-33550

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-22 02:16:56
Last updated 2026-03-23 15:53:19
Assigner mitre
State PUBLISHED

Description

SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommended).