7.1
CVE-2026-75002
- EPSS 1.32%
- Veröffentlicht 17.08.2026 12:48:41
- Zuletzt bearbeitet 08.09.2026 18:59:00
- Erkennungen
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.32% | 0.685 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 7.1 | 1.6 | 5.5 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
https://github.com/roundcube/roundcubemail/releases/tag/1.6.18
https://github.com/roundcube/roundcubemail/releases/tag/1.7.3
https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea
https://github.com/roundcube/roundcubemail/commit/404d43f1b0125319c3cf8c9e3df39074c0cb80ad