← Back to CVE search

CVE-2026-62644

Roundcube Webmail

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS 6.4EPSS 0.259%Risk 0.65
View source
Published
2026-07-14 16:17:04
Affected versions
<1.6.17, <1.7.2
Type
Web application
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N