Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Rule Name Quoting Allows managesieve Disabled Actions Bypass in Roundcube Webmail |
Mon, 17 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin. | |
| First Time appeared |
Roundcube
Roundcube webmail |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roundcube
Roundcube webmail |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-17T14:37:04.784Z
Reserved: 2026-08-17T12:53:49.733Z
Link: CVE-2026-75004
Updated: 2026-08-17T14:37:00.796Z
Status : Received
Published: 2026-08-17T13:16:55.070
Modified: 2026-08-17T15:16:59.793
Link: CVE-2026-75004
No data.
OpenCVE Enrichment
Updated: 2026-08-17T15:00:08Z