CVE-2026-75010 In Roundcube Webmail before 1.6.18 and 1.7.x before… — CVE Notify — TG.ME

🚨 CVE-2026-75010
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

🎖@cveNotify
GitHub
Fix password's modoboa driver leak of an authentication token to a us… · roundcube/roundcubemail@65b8ea9
…er-controlled host
September 8, 2026 28 1