Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-48844

Опубликовано: 25 мая 2026
Источник: debian

Описание

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
roundcubefixed1.6.16+dfsg-1package

Примечания

  • https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1

  • https://github.com/roundcube/roundcubemail/commit/ea1798a6fbf060abcc0ba73b2435036bf8016a5a

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

CVSS3: 7.5
nvd
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

CVSS3: 7.5
github
2 месяца назад

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость реализации протокола LDAP почтового клиента RoundCube Webmail, позволяющая нарушителю выполнить произвольный код

suse-cvrf
2 месяца назад

Security update for roundcubemail