CVE-2026-75010CWE-669

CVE-2026-75010

Medium · published August 17, 2026

CVSS v3.1
6.4
EPSS
0%
Percentile
20.1
In the wild
Unconfirmed
What it is

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

The record
Technical detail
CVSS v3.1
6.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00279 · 20.1th percentile
Weakness
CWE-669 · Incorrect Resource Transfer Between Spheres
Published
2026-08-17T17:16Z
References (5)
EPSS history
Timeline
  • 17 AUG 13:01Z
    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a…
    cvelistv5