| Name | CVE-2026-75010 |
| Description | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-4760-1, DSA-6479-1 |
| Debian Bugs | 1144059 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| roundcube (PTS) | bullseye | 1.4.15+dfsg.1-1+deb11u4 | vulnerable |
| bullseye (security) | 1.4.15+dfsg.1-1+deb11u11 | fixed | |
| bookworm | 1.6.5+dfsg-1+deb12u9 | vulnerable | |
| bookworm (security) | 1.6.5+dfsg-1+deb12u11 | fixed | |
| trixie | 1.6.16+dfsg-0+deb13u1 | vulnerable | |
| trixie (security) | 1.6.18+dfsg-0+deb13u1 | fixed | |
| forky, sid | 1.6.18+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| roundcube | source | bullseye | 1.4.15+dfsg.1-1+deb11u11 | DLA-4760-1 | ||
| roundcube | source | bookworm | 1.6.5+dfsg-1+deb12u11 | DLA-4760-1 | ||
| roundcube | source | trixie | 1.6.18+dfsg-0+deb13u1 | DSA-6479-1 | ||
| roundcube | source | (unstable) | 1.6.18+dfsg-1 | 1144059 |
Fixed by: https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c (1.6.18)