CVE-2026-74997
published 2026-08-17CVE-2026-74997: In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted…
PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.77%
53.2th percentile
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| roundcube | webmail | >= 1.6.0 < 1.6.18 | 1.6.18 |
| roundcube | webmail | >= 1.7.0 < 1.7.3 | 1.7.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values [epel-all]
bugzilla·2026-08-24·CVSS 8.8
CVE-2026-74997 [HIGH] CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values [epel-all]
CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
Bugzilla
CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values [fedora-all]
bugzilla·2026-08-24·CVSS 8.8
CVE-2026-74997 [HIGH] CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values [fedora-all]
CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
Bugzilla
CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values
bugzilla·2026-08-17·CVSS 8.8
CVE-2026-74997 [HIGH] CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values
CVE-2026-74997 roundcubemail: remote code execution in markasjunk plugin via crafted placeholder values
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
https://github.com/roundcube/roundcubemail/commit/14044f843cfacbe78b042f659e379d6b4497aa7chttps://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2ahttps://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cdhttps://github.com/roundcube/roundcubemail/releases/tag/1.6.18https://github.com/roundcube/roundcubemail/releases/tag/1.7.3https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
2026-08-17
Published