PT-2026-76649 · Unknown · Roundcube Webmail

CVE-2026-75010

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Roundcube Webmail versions prior to 1.6.18 Roundcube Webmail versions 1.7.x prior to 1.7.3
Description The modoboa driver of the password plugin can leak a Modoboa API authentication token to a host controlled by the user through crafted session data. This issue specifically impacts instances configured to use the password plugin with the modoboa driver.
Recommendations Update to version 1.6.18 or later. Update to version 1.7.3 or later. Restrict the use of the modoboa driver within the password plugin as a temporary mitigation.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75010

Affected Products

Roundcube Webmail