CVE-2026-62644
6.4
MEDIUM
CVSS 3.1
EPSS 0.24%
Description
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.
How to fix CVE-2026-62644
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/roundcube—no fix listed
Is CVE-2026-62644 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.4 | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N |