Mail Search Vulnerability in Roundcube Webmail by Roundcube
CVE-2026-75002
7.1HIGH
What is CVE-2026-75002?
A vulnerability in Roundcube Webmail allows for mail search and LITERAL+ byte-count desynchronization. This can be exploited through IMAP command injection, potentially leading to unauthorized information disclosure or privilege escalation. Versions prior to 1.6.18 and 1.7.x before 1.7.3 are affected. Users are urged to update to the latest versions to mitigate the risks associated with this vulnerability.
Affected Version(s)
Webmail 1.6.0 < 1.6.18
Webmail 1.7.0 < 1.7.3
