Missing Authorization in Roundcube Webmail - #VU147189
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote user to modify another user\'s contact group membership.
The vulnerability exists due to improper authorization in SQL address book contact group membership handling when adding or removing group members. A remote user can add or remove contacts from another user\'s group to modify another user\'s contact group membership.