CVE-2026-62644
published 2026-07-14CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.50%
40.9th percentile
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| roundcube | webmail | >= 1.6.0 < 1.6.17 | 1.6.17 |
| roundcube | webmail | >= 1.7.0 < 1.7.2 | 1.7.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Roundcube Webmail up to 1.6.16/1.7.1 Password Plugin Username improper authentication (Nessus ID 327029 / WID-SEC-2026-2207)
vuldb·2026-07-16·CVSS 6.4
CVE-2026-62644 [MEDIUM] Roundcube Webmail up to 1.6.16/1.7.1 Password Plugin Username improper authentication (Nessus ID 327029 / WID-SEC-2026-2207)
A vulnerability categorized as critical has been discovered in Roundcube Webmail up to 1.6.16/1.7.1. Impacted is an unknown function of the component Password Plugin. The manipulation of the argument Username results in improper authentication.
This vulnerability is reported as CVE-2026-62644. The attack can be launched remotely. No exploit exists.
GHSA
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
ghsa_unreviewed·2026-07-14
CVE-2026-62644 [MEDIUM] CWE-290 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin [fedora-all]
bugzilla·2026-07-14·CVSS 6.4
CVE-2026-62644 [MEDIUM] CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin [fedora-all]
CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Bugzilla
CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin [epel-all]
bugzilla·2026-07-14·CVSS 6.4
CVE-2026-62644 [MEDIUM] CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin [epel-all]
CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Bugzilla
CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin
bugzilla·2026-07-14·CVSS 6.4
CVE-2026-62644 [MEDIUM] CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin
CVE-2026-62644 roundcubemail: Roundcube Webmail: Account takeover via username spoofing in password plugin
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4chttps://github.com/roundcube/roundcubemail/commit/7414fef51cd2407d39faab99680763f10ed5231dhttps://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476https://github.com/roundcube/roundcubemail/commit/9a96c20d8c7c9135876b68bebd6960af3ee60923https://github.com/roundcube/roundcubemail/releases/tag/1.6.17https://github.com/roundcube/roundcubemail/releases/tag/1.7.2https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
2026-07-14
Published