PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75007 Roundcube CVE debrief

CVE-2026-75007 is a medium-severity vulnerability in Roundcube Webmail before versions 1.6.18 and 1.7.3. The vulnerability allows for LDAP search filter injection via unescaped %u/%fu/%d substitutions, potentially leading to information disclosure or privilege escalation. System administrators and security teams should review the official CVE Program record and NIST NVD detail page for more information. Affected product deployments should be identified, and owners assigned for follow-up. The CVE record was published on 2026-08-17T13:16:55.410Z and has not been modified since then.

Vendor
Roundcube
Product
Webmail
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-01
Advisory published
2026-08-17
Advisory updated
2026-09-01

Who should care

System administrators and security teams responsible for Roundcube Webmail installations should be aware of this vulnerability and take steps to mitigate it. They should review the official CVE Program record and NIST NVD detail page for more information, identify affected product deployments, and assign owners for follow-up. Security teams should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Additionally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. This includes verifying affected scope, severity, and vendor guidance, as well as confirming whether affected product deployments exist in managed environments. This vulnerability may impact operators, platforms, vulnerability management, and security teams, requiring a thorough review of affected systems and potential impacts on the organization. Security teams should prioritize patching to prevent potential information disclosure or privilege escalation and ensure that all necessary security measures are in place to protect against this vulnerability. This includes reviewing and updating LDAP configuration to prevent injection and monitoring for suspicious activity related to Roundcube Webmail. By taking these steps, security teams can help prevent potential security breaches and ensure the integrity of their systems. Security teams should also consider the potential operational impact of this vulnerability and review the context of this vulnerability to ensure that all necessary security measures are in place. This may involve reviewing compensating controls, monitoring for suspicious activity, and verifying that all necessary patches have been applied. By prioritizing patching and taking a proactive approach to security, organizations can help prevent potential security breaches and protect their systems from this vulnerability. The CVE record was published on 2026-08-17T13:16:55.410Z and has not be

Technical summary

CVE-2026-75007 is a medium-severity vulnerability in Roundcube Webmail before versions 1.6.18 and 1.7.3. The vulnerability allows for LDAP search filter injection via unescaped %u/%fu/%d substitutions, potentially leading to information disclosure or privilege escalation. Official sources, including CVE Program and NIST NVD records, confirm this issue. To address this vulnerability, organizations should apply patches for Roundcube Webmail versions 1.6.18 or 1.7.3, review and update LDAP configuration to prevent injection, and monitor for suspicious activity related to Roundcube Webmail.

Defensive priority

Organizations using Roundcube Webmail should prioritize patching to prevent potential information disclosure or privilege escalation.

Recommended defensive actions

  • Apply patches for Roundcube Webmail versions 1.6.18 or 1.7.3
  • Review and update LDAP configuration to prevent injection
  • Monitor for suspicious activity related to Roundcube Webmail
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE-2026-75007 record indicates a medium-severity vulnerability in Roundcube Webmail before versions 1.6.18 and 1.7.3, allowing for LDAP search filter injection via unescaped substitutions, potentially leading to information disclosure or privilege escalation. Official sources include CVE Program and NIST NVD records.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75007 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75007

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75007 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75007

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.