Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-62644

Опубликовано: 14 июл. 2026
Источник: nvd
CVSS3: 6.4
CVSS3: 9.8
EPSS Низкий

Описание

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Версия от 1.6.0 (включая) до 1.6.17 (исключая)
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Версия от 1.7.0 (включая) до 1.7.2 (исключая)

EPSS

Процентиль: 18%
0.00259
Низкий

6.4 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 6.4
ubuntu
23 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

CVSS3: 6.4
debian
23 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the passwor ...

CVSS3: 6.4
github
22 дня назад

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

EPSS

Процентиль: 18%
0.00259
Низкий

6.4 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-290