CVE-2026-75010: Medium severity Roundcube Roundcube Webmail vulnerability
Published Aug 17, 2026
·Updated
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
Affected Software
2 affected components
Roundcube Roundcube Webmail<1.6.18, >1.6.18<1.7.3
Roundcube Webmail/password plugin (modoboa driver)
Event History
Aug 17, 2026
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-75010?
CVE-2026-75010 has a medium severity rating of 6.4.
2
How do I fix CVE-2026-75010?
To fix CVE-2026-75010, upgrade Roundcube Webmail to version 1.6.18 or 1.7.3 or later.
3
What versions of Roundcube are affected by CVE-2026-75010?
CVE-2026-75010 affects Roundcube Webmail versions prior to 1.6.18 and the 1.7.x series before 1.7.3.
4
What type of data is leaked in CVE-2026-75010?
CVE-2026-75010 could leak a Modoboa API authentication token to a user-controlled host.
5
Which component of Roundcube is involved in CVE-2026-75010?
CVE-2026-75010 involves the modoboa driver of the password plugin in Roundcube.