Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-75004

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Aug 17, 2026
Vendor unknown

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.

References