VYPR
Medium severity6.4NVD Advisory· Published Jul 14, 2026· Updated Jul 20, 2026

CVE-2026-62644

CVE-2026-62644

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

Affected products

2

Patches

Vulnerability mechanics

References

7

News mentions

1