Intel

AIKIDO-2026-988498

roundcube/roundcubemail is vulnerable to Remote Code Execution (RCE)

Remote Code Execution (RCE)CVE-2026-74997 Published Today

88

High Risk

This Affects:

PHProundcube/roundcubemail
1.6.0 - 1.7.2
Fixed in 1.7.3
Are you affected? Scan for Free

TL;DR

Roundcube 1.7.3 fixes eleven security issues affecting the webmail core and plugins, including **remote code execution, IMAP command injection, SSRF, stored XSS, LDAP filter injection, and sensitive information disclosure**. The most severe issue, **CVE-2026-74997**, allows remote code execution through the markasjunk plugin, while others allow attackers to bypass SSRF and remote-content protections, inject commands or filters, bypass Sieve restrictions, or expose API credentials.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

roundcube/roundcubemail is vulnerable to Remote Code Execution (RCE) in versions 1.6.0 - 1.7.2.

How to fix this

Upgrade the roundcube/roundcubemail library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform