Sceawere

Vulnerability Detail

CVE-2026-74997UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Roundcube Markasjunk RCE Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
8h ago
Vendor
Roundcube
Product
Webmail
Attack Type
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-17T13:16:54.100Z",
  "pubdate": "2026-08-17T13:16:54.100Z",
  "executiveSummary": "A remote code execution vulnerability exists in Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3. The vulnerability resides within the markasjunk plugin specifically utilizing the cmd_learn driver. Attackers capable of interacting with the affected system can achieve remote code execution through the manipulation of crafted placeholder replacement values. This flaw impacts the integrity, confidentiality, and availability of the underlying server hosting the vulnerable Roundcube instances. The risk implication is severe, as successful exploitation allows arbitrary command execution with the privileges of the web server process. Exploitation is constrained to instances explicitly configured to use the vulnerable markasjunk plugin with the cmd_learn driver. Mitigation requires updating Roundcube to the patched versions where the placeholder replacement values in the command-learning driver are properly sanitized or handled to prevent command injection vectors.",
  "technicalDetails": "The vulnerability is caused by improper neutralization of user-supplied data or placeholder replacement values within the cmd_learn driver of the markasjunk plugin in Roundcube Webmail. Affected software versions include Roundcube Webmail prior to 1.6.18 and versions in the 1.7.x branch prior to 1.7.3. The vulnerable component is strictly isolated to the markasjunk plugin when configured to utilize the cmd_learn driver for processing email classification actions.\nThe attack flow proceeds as follows: an attacker crafts malicious input containing specially designed placeholder replacement values. When the markasjunk plugin processes this input via the cmd_learn driver, the unsanitized or improperly handled values are concatenated or passed directly into system command execution contexts. Because the application fails to adequately validate or escape these values, the underlying operating system executes the attacker-supplied payload as part of the command string.\nThis vulnerability enables remote code execution without requiring prior authentication, depending on the exposure of the webmail interface and the specific interaction required by the plugin's trigger mechanism. The post-exploitation impact includes full system compromise of the web server, potential lateral movement within the internal network, unauthorized access to sensitive user emails, session hijacking, and manipulation of system configurations. Network exposure is inherent to any deployment where the Roundcube webmail interface is accessible to users over the network and the specific plugin and driver combination is enabled."
}
CVE-2026-74997: Roundcube Markasjunk RCE Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere