CVE-2026-75004: Command Injection
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesievedisabledactions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.6.18 - Upgrade
Upgrade
Roundcube Webmailto a version that resolves this vulnerability.Fixed in 1.7.3 - Compensating control
If you cannot immediately upgrade, ensure access to the Roundcube instances that use the managesieve plugin is limited/isolated to trusted users while remediation is in progress.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-75004?
The severity of CVE-2026-75004 is classified as medium with a score of 4.3.
How do I fix CVE-2026-75004?
To fix CVE-2026-75004, upgrade to Roundcube Webmail version 1.6.18 or 1.7.3 or later.
What impact does CVE-2026-75004 have on Roundcube Webmail?
CVE-2026-75004 can potentially allow attackers to bypass the managesieve_disabled_actions setting through crafted rule names in Sieve scripts.
Which version of Roundcube Webmail is affected by CVE-2026-75004?
CVE-2026-75004 affects Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3.
Is the managesieve plugin necessary to be vulnerable to CVE-2026-75004?
Yes, the vulnerability only affects Roundcube instances that are using the managesieve plugin.