PT-2026-76649 · Unknown · Roundcube Webmail
CVE-2026-75010
·
Published
2026-08-17
·
Updated
2026-08-17
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Roundcube Webmail versions prior to 1.6.18
Roundcube Webmail versions 1.7.x prior to 1.7.3
Description
The modoboa driver of the password plugin can leak a Modoboa API authentication token to a host controlled by the user through crafted session data. This issue specifically impacts instances configured to use the password plugin with the modoboa driver.
Recommendations
Update to version 1.6.18 or later.
Update to version 1.7.3 or later.
Restrict the use of the modoboa driver within the password plugin as a temporary mitigation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Roundcube Webmail