๐Ÿ” CVE Alert

CVE-2026-74997

HIGH 8.8
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

CWE CWE-78
Vendor roundcube
Product webmail
Published Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for roundcube webmail

Be the first to know when new high vulnerabilities affecting roundcube webmail are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Roundcube / Webmail
1.6.0 < 1.6.18 1.7.0 < 1.7.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
roundcube.net: https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3 github.com: https://github.com/roundcube/roundcubemail/releases/tag/1.6.18 github.com: https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd github.com: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a github.com: https://github.com/roundcube/roundcubemail/releases/tag/1.7.3 github.com: https://github.com/roundcube/roundcubemail/commit/14044f843cfacbe78b042f659e379d6b4497aa7c