CVE-2026-62644 - Roundcube Webmail Password Plugin Username Spoofing Vulnerability
CVE ID :CVE-2026-62644
Published : July 14, 2026, 4:17 p.m. | 30 minutes ago
Description :In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 14, 2026, 4:17 p.m. | 30 minutes ago
Description :In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Severity: 6.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...