ZeroHour

CVE-2026-62644

CVSS 3.1
9.8 critical
EPSS
<1%p41
Published
()
Modified
Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

Vendors
roundcube
Products
webmail
Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.