← Volver al buscador de CVEs

CVE-2026-62644

Roundcube Webmail

Descripción

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS 6.4EPSS 0.259%Riesgo 0.65
Ver fuente
Publicación
2026-07-14 16:17:04
Versiones afectadas
<1.6.17, <1.7.2
Tipo
Aplicación web
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N