Description
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
Published: 2026-08-17
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Roundcube Webmail instances that use the password plugin with the modoboa driver can leak a Modoboa API authentication token through crafted session data. The leaked token is sent to a host controlled by an attacker, enabling the attacker to authenticate to the Modoboa system with elevated privileges. This vulnerability represents an information disclosure that can compromise the confidentiality of authentication credentials and potentially lead to unauthorized actions on the affected system.

Affected Systems

The vulnerability affects Roundcube Webmail versions prior to 1.6.18 and all 1.7.x releases before 1.7.3. Only Roundcube installations that have the password plugin enabled with the modoboa driver are impacted. Earlier versions or installations without the plugin are not affected.

Risk and Exploitability

The CVSS score of 6.4 indicates a medium impact, and the EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is listed in the CISA KEV catalog as not listed, suggesting no known public exploitation. The attack would require an attacker to target a Roundcube instance that uses the vulnerable plugin and craft session data to trigger the token leak, with the token then being forwarded to any host reachable by the victim server. Because the exploit hinges on web session manipulation, it could be carried out remotely against exposed webmail servers.

Generated by OpenCVE AI on August 17, 2026 at 14:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Roundcube Webmail to version 1.6.18 or later 1.7.3 where the password plugin modoboa driver is fixed.
  • If an upgrade is not immediately possible, remove or disable the password plugin modoboa driver so the vulnerable code path is not executed.
  • Implement network filtering to block outbound traffic from the webmail server to external hosts that could receive the leaked token, as a temporary measure.

Generated by OpenCVE AI on August 17, 2026 at 14:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Roundcube Webmail Password Plugin Modoboa Driver Token Leakage

Mon, 17 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.
First Time appeared Roundcube
Roundcube webmail
Weaknesses CWE-669
CPEs cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:*
Vendors & Products Roundcube
Roundcube webmail
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Roundcube Webmail
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T14:11:00.263Z

Reserved: 2026-08-17T13:01:26.319Z

Link: CVE-2026-75010

cve-icon Vulnrichment

Updated: 2026-08-17T14:10:56.215Z

cve-icon NVD

Status : Received

Published: 2026-08-17T13:16:55.563

Modified: 2026-08-17T14:20:22.597

Link: CVE-2026-75010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:00:08Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres