CVE-2026-74999 | Roundcube Webmail up to 1.6.17/1.7.2 Address Book cross site scripting

SecurityVulns

A vulnerability described as problematic has been identified in Roundcube Webmail up to 1.6.17/1.7.2. Affected by this vulnerability is an unknown functionality of the component Address Book. Executing a manipulation can lead to cross site scripting.

This vulnerability is registered as CVE-2026-74999. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More