CVE-2026-62642: Medium severity Roundcube Roundcube Webmail vulnerability
Published Jul 14, 2026
·Updated
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
Affected Software
3 affected components
Roundcube Roundcube Webmail<1.6.17, >1.7.0<1.7.2
Roundcube Webmail>=1.6.0<1.6.17
Roundcube Webmail>=1.7.0<1.7.2
Remediation
Event History
Jul 14, 2026
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-62642?
CVE-2026-62642 has a medium severity rating of 4.3.
2
What are the risks associated with CVE-2026-62642?
CVE-2026-62642 can lead to a denial of service when an email with a TNEF attachment is opened.
3
How do I fix CVE-2026-62642?
To fix CVE-2026-62642, upgrade Roundcube Webmail to version 1.6.17 or 1.7.2 and later.
4
Which versions of Roundcube are affected by CVE-2026-62642?
CVE-2026-62642 affects Roundcube Webmail versions prior to 1.6.17 and 1.7.x before 1.7.2.
5
What is the nature of the vulnerability in CVE-2026-62642?
CVE-2026-62642 is an infinite loop vulnerability in the TNEF decoder of Roundcube Webmail.