What is CVE-2026-75002?
This critical vulnerability affects older versions of Roundcube Webmail. An attacker can achieve information disclosure or privilege escalation via IMAP command injection during mail search due to byte-count desynchronization. Immediate update to versions 1.6.18 or 1.7.3 is strongly recommended.
Azərbaycanca: Bu kritik zəiflik Roundcube Webmail-in köhnə versiyalarında aşkarlanıb. Təcavüzkar poçt axtarışı zamanı IMAP əmr injeksiyası vasitəsilə məlumat sızmasına və ya imtiyaz yüksəltməyə nail ola bilər. Dərhal 1.6.18 və ya 1.7.3 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
During which email operation is CVE-2026-75002 exploited?
It is exploited via IMAP command injection during mail search.
To which versions should Roundcube Webmail be updated to protect against this vulnerability?
It is strongly recommended to update to versions 1.6.18 or 1.7.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.