Missing Authorization in Roundcube Webmail - #VU147189

 

Missing Authorization in Roundcube Webmail - #VU147189

Published: September 6, 2026


Vulnerability identifier: #VU147189
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify another user\'s contact group membership.

The vulnerability exists due to improper authorization in SQL address book contact group membership handling when adding or removing group members. A remote user can add or remove contacts from another user\'s group to modify another user\'s contact group membership.


Affected software

Roundcube Webmail

Remediation

Install security update from vendor's website.

Roundcube Webmail - addressed in versions 1.6.19, 1.7.4

External References

Related Security Bulletins