Medium severity6.4NVD Advisory· Published Jul 14, 2026· Updated Jul 20, 2026
CVE-2026-62644
CVE-2026-62644
Description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Affected products
2- Range: <1.6.17, <1.7.2
Patches
Vulnerability mechanics
References
7- github.com/roundcube/roundcubemail/commit/5cdc6a48b40beabff7f0bf5d9035f4491e877e4cnvdPatch
- github.com/roundcube/roundcubemail/commit/7414fef51cd2407d39faab99680763f10ed5231dnvdPatch
- github.com/roundcube/roundcubemail/commit/83150ce04d689a70f92d511bcae40adba8d55476nvdPatch
- github.com/roundcube/roundcubemail/commit/9a96c20d8c7c9135876b68bebd6960af3ee60923nvdPatch
- roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2nvdVendor Advisory
- github.com/roundcube/roundcubemail/releases/tag/1.6.17nvdRelease Notes
- github.com/roundcube/roundcubemail/releases/tag/1.7.2nvdRelease Notes
News mentions
1- Roundcube Webmail: Four Vulnerabilities Disclosed, Ranging from DoS to Account TakeoverVypr Intelligence · Jul 15, 2026