Session Data Vulnerability in Roundcube Webmail Affects User Authentication
CVE-2026-75010

6.4MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-75010?

In certain versions of Roundcube Webmail, particularly those utilizing the password plugin with the Modoboa driver, a vulnerability exists allowing an attacker to exploit crafted session data. This flaw could potentially leak a Modoboa API authentication token to user-controlled hosts, posing a significant security risk for instances of Roundcube Webmail. Users are advised to update to at least versions 1.6.18 or 1.7.3 to mitigate this vulnerability.

Affected Version(s)

Webmail 1.6.0 < 1.6.18

Webmail 1.7.0 < 1.7.3

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.