← Späť na vyhľadávanie CVE

CVE-2026-62644

Roundcube Webmail

Popis

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS 6.4EPSS 0.259%Riziko 0.65
Zobraziť zdroj
Zverejnené
2026-07-14 16:17:04
Dotknuté verzie
<1.6.17, <1.7.2
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N