THREAT OPS › Threat News › [NVD] CVE-2026-8496 (MEDIUM 6.1) — A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the descrip
[NVD] CVE-2026-8496 (MEDIUM 6.1) — A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the descrip
CVE-2026-8496 CVSS: 6.1 MEDIUM Published: 2026-05-13T19:17:30.700
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS file, with an onrepeat event han
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-8496cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-8496