Deserialization of Untrusted Data in Roundcube Webmail - #VU124136
Published: March 19, 2026
Roundcube Webmail
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code or write arbitrary files.
The vulnerability exists due to unsafe deserialization in redis/memcache session handler when processing session data. A remote attacker can send a specially crafted session payload to execute arbitrary code or write arbitrary files.
No authentication is required to exploit this vulnerability.