What is CVE-2026-75004?
CVE-2026-75004 is a vulnerability in Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, affecting instances using the managesieve plugin. Improper rule name quoting allows bypassing the managesieve_disabled_actions setting via a crafted Sieve script rule name. Users should update Roundcube to the patched versions.
Azərbaycanca: CVE-2026-75004 Roundcube Webmail-in 1.6.18-dən əvvəl və 1.7.x-in 1.7.3-dən əvvəlki versiyalarında, managesieve plugin-i istifadə edən sistemlərdə aşkarlanan boşluqdur. Sieve skriptində xüsusi hazırlanmış rule name vasitəsilə managesieve_disabled_actions parametrinin bypass edilməsinə imkan verir. İstifadəçilərə Roundcube-i ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: Roundcube
FAQ2
Which versions of Roundcube Webmail are affected by CVE-2026-75004?
This vulnerability affects Roundcube Webmail versions before 1.6.18 and versions in the 1.7.x branch before 1.7.3.
What can an attacker achieve by exploiting CVE-2026-75004?
An attacker can bypass the managesieve_disabled_actions setting by using a crafted Sieve script rule name.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.