CVE-2026-62644

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*

History

20 Jul 2026, 12:41

Type Values Removed Values Added
References () https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c - () https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c - Patch
References () https://github.com/roundcube/roundcubemail/commit/7414fef51cd2407d39faab99680763f10ed5231d - () https://github.com/roundcube/roundcubemail/commit/7414fef51cd2407d39faab99680763f10ed5231d - Patch
References () https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476 - () https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476 - Patch
References () https://github.com/roundcube/roundcubemail/commit/9a96c20d8c7c9135876b68bebd6960af3ee60923 - () https://github.com/roundcube/roundcubemail/commit/9a96c20d8c7c9135876b68bebd6960af3ee60923 - Patch
References () https://github.com/roundcube/roundcubemail/releases/tag/1.6.17 - () https://github.com/roundcube/roundcubemail/releases/tag/1.6.17 - Release Notes
References () https://github.com/roundcube/roundcubemail/releases/tag/1.7.2 - () https://github.com/roundcube/roundcubemail/releases/tag/1.7.2 - Release Notes
References () https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2 - () https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2 - Vendor Advisory
First Time Roundcube webmail
Roundcube
CPE cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*

14 Jul 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 16:17

Updated : 2026-07-20 12:41


NVD link : CVE-2026-62644

Mitre link : CVE-2026-62644

CVE.ORG link : CVE-2026-62644


JSON object : View

Products Affected

roundcube

  • webmail
CWE
CWE-290

Authentication Bypass by Spoofing