CVE-2026-75010
Received Received - Intake

Password Plugin Modoboa Driver Token Leak in Roundcube Webmail

Vulnerability report for CVE-2026-75010, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: MITRE

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
roundcube roundcube to 1.6.18 (exc)
roundcube roundcube From 1.7.0 (inc) to 1.7.3 (exc)
modoboa modoboa *
roundcube webmail to 1.6.18 (exc)
roundcube webmail From 1.7.0 (inc) to 1.7.3 (exc)
modoboa password_plugin *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-669 The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Roundcube Webmail versions before 1.6.18 and 1.7.x before 1.7.3. It involves the password plugin's modoboa driver leaking a Modoboa API authentication token to a user-controlled host through crafted session data. Only instances using the password plugin with the modoboa driver are impacted.

Impact Analysis

An attacker could exploit this to gain unauthorized access to Modoboa API resources by obtaining the leaked authentication token. This may allow them to perform actions on behalf of the compromised user, potentially leading to data breaches or unauthorized modifications.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements under GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Update Roundcube Webmail to version 1.6.18 or later if using 1.6.x, or to version 1.7.3 or later if using 1.7.x. Disable the password plugin's modoboa driver if not required. Review logs for suspicious session data exchanges.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75010. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart