In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
Metrics
Affected Vendors & Products
References
History
Sat, 01 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Roundcube Webmail Password Plugin Allows Username Spoofing and Account Takeover |
Sat, 25 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Roundcube Webmail Password Plugin Allows Username Spoofing and Account Takeover |
Fri, 24 Jul 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Roundcube Username Spoofing via Session Data Manipulation |
Fri, 17 Jul 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Roundcube Username Spoofing via Session Data Manipulation |
Tue, 14 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jul 2026 16:15:00 +0000
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-07-14T17:15:20.139Z
Reserved: 2026-07-14T15:55:22.524Z
Link: CVE-2026-62644
Updated: 2026-07-14T17:15:15.993Z
Status : Analyzed
Published: 2026-07-14T16:17:04.810
Modified: 2026-07-20T12:41:22.573
Link: CVE-2026-62644
No data.
OpenCVE Enrichment
Updated: 2026-08-01T10:00:04Z