CVE-2026-75002: Command Injection
Published Aug 17, 2026
·Updated
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
Affected Software
1 affected component
Roundcube Roundcube Webmail<1.6.18, >1.7.0<1.7.3
Event History
Aug 17, 2026
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-75002?
The severity of CVE-2026-75002 is rated as high with a score of 7.1.
2
What types of vulnerabilities are associated with CVE-2026-75002?
CVE-2026-75002 is associated with command injection vulnerabilities leading to information disclosure or privilege escalation.
3
How do I fix CVE-2026-75002?
To fix CVE-2026-75002, upgrade your Roundcube Webmail to version 1.6.18 or 1.7.3 or later.
4
What versions of Roundcube are affected by CVE-2026-75002?
CVE-2026-75002 affects Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3.
5
What are the potential impacts of exploiting CVE-2026-75002?
Exploiting CVE-2026-75002 could lead to unauthorized access to sensitive information or privilege escalation within the system.