CVE-2026-62644

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-14 16:17

Updated : 2026-07-20 12:41


NVD link : CVE-2026-62644

Mitre link : CVE-2026-62644

CVE.ORG link : CVE-2026-62644


JSON object : View

Products Affected

roundcube

  • webmail
CWE
CWE-290

Authentication Bypass by Spoofing