CVE-2026-75004
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Aug 17, 2026
Vendor
unknown
Description
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.