CVE-2026-62644

MEDIUM

Roundcube Webmail - Authentication Bypass by Spoofing

Title source: rule
STIX 2.1

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

Scores

CVSS v3 6.4
EPSS 0.0026
EPSS Percentile 17.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-290
Status published
Products (3)
Roundcube/Webmail 1.6.0 - 1.6.17
roundcube/webmail 1.6.0 - 1.6.17
Roundcube/Webmail 1.7.0 - 1.7.2
Published Jul 14, 2026
Tracked Since Jul 14, 2026