Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-62644

Опубликовано: 14 июл. 2026
Источник: debian
EPSS Низкий

Описание

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
roundcubefixed1.6.17+dfsg-1package

Примечания

  • https://github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476 (1.6.17)

  • https://github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4c (1.6.17)

EPSS

Процентиль: 18%
0.00259
Низкий

Связанные уязвимости

CVSS3: 6.4
ubuntu
23 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS3: 6.4
nvd
23 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS3: 6.4
github
22 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

EPSS

Процентиль: 18%
0.00259
Низкий