CVE-2026-62644
קריטית 9.8
תיאור (מקור, אנגלית)
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-14/8/2026
- CWE
- CWE-290
מוצרים מושפעים
roundcube: webmail
קישורים
- https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2 Vendor Advisory
- https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035… Patch
- https://github.com/roundcube/roundcubemail/commit/7414fef51cd2407d39faab996807… Patch
- https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae4… Patch
- https://github.com/roundcube/roundcubemail/commit/9a96c20d8c7c9135876b68bebd69… Patch
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.17 Release Notes
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.2 Release Notes