Help Ukraine, click for information

CVE-2026-62644

cve@mitre.org
MEDIUM
CVSS Score:6.4/10
Analyzed
Published: 7/14/2026
Modified: 7/20/2026
2 Affected Products
Risk Assessment
70%
Exploitability
90%
Impact
Overall Risk: 64%
Vulnerability Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS v3.1 Score
6.4
MEDIUM
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
1.2
Exploitability
5.2
Impact
Attack Vector Analysis
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

> Thanks for visiting. Stay curious and stay secure. _