Impact
The Roundcube Webmail password plugin in versions older than 1.6.17 and 1.7.2 contains an authentication bypass that allows an attacker to modify session data to impersonate another user. By spoofing the username stored in the session, the attacker can gain access to an account without needing the proper credentials. This weakness is identified as a CWE‑290 flaw where the system fails to verify the user’s identity before granting access.
Affected Systems
All installations of Roundcube Webmail 1.6.x before 1.6.17 and 1.7.x before 1.7.2 that employ the default password plugin are vulnerable. Sites running these versions and relying on the built‑in authentication mechanism must address the issue promptly.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity level, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not included in CISA's KEV catalog, implying no widespread public exploits have been identified. Based on the description, it is inferred that the attack path requires the ability to influence session data, which could be achieved through remote access to the application or by social engineering tactics that allow the attacker to obtain a valid session. If such access is gained, the attacker can impersonate any user and hijack the associated account.
OpenCVE Enrichment
Debian DLA
Debian DSA