CVE-2026-74999 | Roundcube Webmail up to 1.6.17/1.7.2 Address Book cross site scripting
A vulnerability described as problematic has been identified in Roundcube Webmail up to 1.6.17/1.7.2. Affected by this vulnerability is an unknown functionality of the component Address Book. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2026-74999. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More