CVE-2026-74997 - Roundcube Webmail Markasjunk Plugin Remote Code Execution Vulnerability
Brief
CVE ID : CVE-2026-74997
Published : Aug. 17, 2026, 12:37 p. m.
- 30 minutes ago
Description : In Roundcube Webmail before 1.
- 18 and 1.
- x before 1.
- 3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
Severity: 8.8
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
