CVE-2026-62644
MEDIUM severity · CVSS 6.4 · CWE-290
6.4CVSS MEDIUM
Summary
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges requiredLow
User interactionRequired
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
Exploit probability (EPSS)0%
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c ↗
Additional information
- NVD record
- https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4cPatch
- https://github.com/roundcube/roundcubemail/commit/7414fef51cd2407d39faab99680763f10ed5231dPatch
- https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476Patch
- https://github.com/roundcube/roundcubemail/commit/9a96c20d8c7c9135876b68bebd6960af3ee60923Patch
- https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2Advisory
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.17
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.2