SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-75004

MEDIUM · CVSS 4.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Roundcube Webmail versions prior to 1.6.18 and 1.7.x before 1.7.3 are vulnerable due to improper quoting of rule names, which can allow attackers to bypass the managesieve_disabled_actions setting through a specially crafted Sieve script. This vulnerability poses a medium risk, potentially enabling unauthorized actions within the email management system. Organizations using the managesieve plugin in their Roundcube instances should prioritize patching to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75004
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.

Related CVEs

Other vulnerabilities affecting the same vendor(s)