What is CVE-2026-74997?
This is a critical Remote Code Execution vulnerability in the cmd_learn driver of the markasjunk plugin for Roundcube Webmail. It is triggered by crafted placeholder replacement values and only affects instances using the markasjunk plugin with its cmd_learn driver. All affected users must update to versions 1.6.18 or 1.7.3 immediately.
Azərbaycanca: Roundcube Webmail-in markasjunk plaqinindəki cmd_learn sürücüsündə xüsusi hazırlanmış placeholder-lər vasitəsilə uzaqdan kod icrasına (Remote Code Execution) yol açan kritik boşluqdur. Bu, yalnız cmd_learn sürücüsü aktiv olan markasjunk plaqinindən istifadə edən Roundcube instansiyalarına təsir edir. Bütün istifadəçilər dərhal 1.6.18 və ya 1.7.3 versiyalarına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which specific plugin and driver must be active for a Roundcube Webmail instance to be affected by CVE-2026-74997?
Only Roundcube instances using the markasjunk plugin with its cmd_learn driver are affected.
What versions of Roundcube should users update to in order to fix CVE-2026-74997?
All affected users must immediately update to versions 1.6.18 or 1.7.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.