CVE-2026-62644 UNKNOWN

CVE-2026-62644

Published: 2026-07-14

Description

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…