CVE-2026-62644
MEDIUMRoundcube Webmail - Authentication Bypass by Spoofing
Title source: ruleDescription
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
References (7)
Core 7
Scores
CVSS v3
6.4
EPSS
0.0026
EPSS Percentile
17.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-290
Status
published
Products (3)
Roundcube/Webmail
1.6.0 - 1.6.17
roundcube/webmail
1.6.0 - 1.6.17
Roundcube/Webmail
1.7.0 - 1.7.2
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026