CVE-2026-75004
EUVD-2026-6017017.08.2026, 13:16
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| roundcube | webmail | 1.6.0 ≤ 𝑥 < 1.6.18 | CNA |
| roundcube | webmail | 1.7.0 ≤ 𝑥 < 1.7.3 | CNA |
Debian Releases