Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-75010

MEDIUM NVD
CVSS Score 6.4
Severity MEDIUM
Published Aug 17, 2026
Vendor unknown

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

References