CVE-2026-74999: XSS
Published Aug 17, 2026
·Updated
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
Affected Software
2 affected components
Roundcube Roundcube Webmail<1.6.18
Roundcube Roundcube Webmail>1.7.0<1.7.3
Event History
Aug 17, 2026
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-74999?
The severity of CVE-2026-74999 is classified as medium with a score of 5.4.
2
How do I fix CVE-2026-74999?
To fix CVE-2026-74999, update Roundcube Webmail to version 1.6.18 or 1.7.3 or later.
3
What type of vulnerability is CVE-2026-74999?
CVE-2026-74999 is categorized as a stored Cross-Site Scripting (XSS) vulnerability.
4
Which versions of Roundcube are affected by CVE-2026-74999?
CVE-2026-74999 affects Roundcube Webmail versions prior to 1.6.18 and 1.7.x before 1.7.3.
5
What impact does CVE-2026-74999 have on users?
CVE-2026-74999 may allow attackers to execute arbitrary scripts in the context of a user's session through the 'Add to address book' feature.