CVE-2026-62644: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the passwor ...

Severity: Critical

CVSS Score: 9.8

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.