CVE-2026-62644 | Roundcube Webmail up to 1.6.16/1.7.1 Password Plugin Username improper authentication
A vulnerability categorized as critical has been discovered in Roundcube Webmail up to 1.6.16/1.7.1. Impacted is an unknown function of the component Password Plugin. The manipulation of the argument Username results in improper authentication.
This vulnerability is reported as CVE-2026-62644. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More