What is CVE-2026-75010?
A vulnerability in the 'modoboa' driver of Roundcube Webmail's 'password' plugin could leak an API authentication token to a user-controlled host via crafted session data. This issue affects instances using the specific driver and is fixed in versions 1.6.18 and 1.7.3.
Azərbaycanca: Roundcube Webmail-in 'password' plugin-inin 'modoboa' driver-ində kritik zəiflik aşkarlanıb. Bu, API autentifikasiya token-inin xüsusi hazırlanmış session məlumatı vasitəsilə istifadəçi tərəfindən idarə olunan host-a sızmasına səbəb ola bilər. Təsirə məruz qalan versiyaları işlədən istifadəçilər dərhal 1.6.18 və ya 1.7.3 versiyalarına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which component of Roundcube Webmail is affected by CVE-2026-75010?
This vulnerability affects the 'modoboa' driver of Roundcube Webmail's 'password' plugin.
To which versions should users patch to mitigate CVE-2026-75010?
Affected users should immediately update to versions 1.6.18 or 1.7.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.