roundcube/roundcubemail is vulnerable to Remote Code Execution (RCE)
88
High Risk
Roundcube 1.7.3 fixes eleven security issues affecting the webmail core and plugins, including **remote code execution, IMAP command injection, SSRF, stored XSS, LDAP filter injection, and sensitive information disclosure**. The most severe issue, **CVE-2026-74997**, allows remote code execution through the markasjunk plugin, while others allow attackers to bypass SSRF and remote-content protections, inject commands or filters, bypass Sieve restrictions, or expose API credentials.
You are affected if you are using a version that falls within the vulnerable range.
roundcube/roundcubemail is vulnerable to Remote Code Execution (RCE) in versions 1.6.0 - 1.7.2.
Upgrade the roundcube/roundcubemail library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.