Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-74997

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Aug 17, 2026
Vendor unknown

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

References