Cyber Attack·Cloud & SaaSBreakingSOGo Groupware Proxy Authentication Flaw Allows Unauthenticated Account Impersonation via WebObjects Header (CVE-2026-74864)An authentication bypass in SOGo groupware allows remote attackers to impersonate any user without credentials by supplying an unsanitized x-webobjects-remote-user header.CST Newsroom1 Oct 202611 min read