In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
References
Configurations
Configuration 1 (hide)
|
History
20 Jul 2026, 12:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c - Patch | |
| References | () https://github.com/roundcube/roundcubemail/commit/7414fef51cd2407d39faab99680763f10ed5231d - Patch | |
| References | () https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476 - Patch | |
| References | () https://github.com/roundcube/roundcubemail/commit/9a96c20d8c7c9135876b68bebd6960af3ee60923 - Patch | |
| References | () https://github.com/roundcube/roundcubemail/releases/tag/1.6.17 - Release Notes | |
| References | () https://github.com/roundcube/roundcubemail/releases/tag/1.7.2 - Release Notes | |
| References | () https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2 - Vendor Advisory | |
| First Time |
Roundcube webmail
Roundcube |
|
| CPE | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* |
14 Jul 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 16:17
Updated : 2026-07-20 12:41
NVD link : CVE-2026-62644
Mitre link : CVE-2026-62644
CVE.ORG link : CVE-2026-62644
JSON object : View
Products Affected
roundcube
- webmail
CWE
CWE-290
Authentication Bypass by Spoofing
