Information disclosure in Roundcube Webmail - #VU141376
Published: August 9, 2026
Vulnerability details
The vulnerability allows a remote user to disclose an authentication token to a user-controlled host.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in the modoboa driver when contacting a user-controlled host. A remote user can cause the password feature to contact a user-controlled host to disclose an authentication token.