Sceawere

Vulnerability Detail

CVE-2026-75010UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Roundcube Password Plugin Authentication Token Leak

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
8h ago
Vendor
Roundcube
Product
Webmail
Attack Type
CWE-669 Incorrect Resource Transfer Between Spheres
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-08-17T13:16:55.563Z",
  "pubdate": "2026-08-17T13:16:55.563Z",
  "executiveSummary": "A credential exposure vulnerability exists in Roundcube Webmail before versions 1.6.18 and 1.7.x before 1.7.3, specifically within the password plugin's modoboa driver. The flaw enables the leakage of a sensitive Modoboa API authentication token to an external, user-controlled host.\nThe primary impact of this vulnerability is the unauthorized exposure of API authentication tokens, which could lead to secondary compromise of the integrated Modoboa backend depending on token privileges.\nThis issue affects Roundcube instances utilizing the password plugin specifically configured with the modoboa driver.\nThe risk implications involve unauthorized token exfiltration, potentially exposing administrative or user session contexts associated with the Modoboa API.\nAn attacker must be capable of injecting or supplying crafted session data to trigger the outbound transmission of the token to an external destination.\nExploitation requires the target Roundcube instance to have the password plugin enabled using the vulnerable modoboa driver.",
  "technicalDetails": "The vulnerability resides in the modoboa driver of the password plugin within Roundcube Webmail. The root cause stems from improper handling and sanitization of session data, which allows sensitive application state variables to be leaked.\nSpecifically, the modoboa driver incorrectly processes user-controlled or influenced session data in a manner that facilitates the transmission of a Modoboa API authentication token to an external, attacker-controlled host.\nThe attack flow proceeds as follows: First, the attacker crafts malicious session data containing parameters designed to interact with the modoboa driver's communication logic. Second, the attacker injects this crafted session data into the Roundcube application context. Third, when the application processes the affected session state via the password plugin's modoboa driver, it inadvertently includes the sensitive Modoboa API authentication token in outbound requests directed toward the user-controlled host.\nAffected software versions include Roundcube Webmail prior to 1.6.18 and 1.7.x prior to 1.7.3.\nThe vulnerable component is the password plugin's modoboa driver responsible for interfacing with the Modoboa service.\nNetwork exposure depends on the accessibility of the Roundcube web interface and the plugin's ability to trigger outbound HTTP or network connections based on session parameters.\nThe payload behavior involves manipulating session variables to redirect or leak sensitive API tokens during backend communication routines.\nPost-exploitation impact includes the acquisition of the Modoboa API authentication token by an unauthorized party, potentially allowing subsequent unauthorized interactions with the connected Modoboa instance."
}
CVE-2026-75010: Roundcube Password Plugin Authentication Token Leak (MEDIUM Severity, CVSS: 6.4) - Sceawere