CVE-2026-75007: Command Injection
Published Aug 17, 2026
·Updated
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.
Affected Software
1 affected component
Roundcube Roundcube Webmail<1.6.18, >1.7.0<1.7.3
Event History
Aug 17, 2026
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-75007?
CVE-2026-75007 has a medium severity rating of 5.4.
2
How do I fix CVE-2026-75007?
To fix CVE-2026-75007, you should upgrade Roundcube Webmail to version 1.6.18 or later in the 1.7.x series.
3
What vulnerabilities are associated with CVE-2026-75007?
CVE-2026-75007 is associated with command injection vulnerabilities that can lead to information disclosure or privilege escalation.
4
What versions of Roundcube are affected by CVE-2026-75007?
CVE-2026-75007 affects Roundcube Webmail versions prior to 1.6.18 and 1.7.x before 1.7.3.
5
What types of attacks can occur due to CVE-2026-75007?
Attacks exploiting CVE-2026-75007 may result in information disclosure or privilege escalation.