Session Data Vulnerability in Roundcube Webmail Affects User Authentication
CVE-2026-75010
6.4MEDIUM
What is CVE-2026-75010?
In certain versions of Roundcube Webmail, particularly those utilizing the password plugin with the Modoboa driver, a vulnerability exists allowing an attacker to exploit crafted session data. This flaw could potentially leak a Modoboa API authentication token to user-controlled hosts, posing a significant security risk for instances of Roundcube Webmail. Users are advised to update to at least versions 1.6.18 or 1.7.3 to mitigate this vulnerability.
Affected Version(s)
Webmail 1.6.0 < 1.6.18
Webmail 1.7.0 < 1.7.3
