Looking for the vulnerability index of Invicti's legacy products?
Roundcube Authentication Bypass by Spoofing Vulnerability - CVE-2026-62644 - Vulnerability Database

Roundcube Authentication Bypass by Spoofing Vulnerability - CVE-2026-62644

Critical
Reference: CVE-2026-62644
Title: Roundcube Authentication Bypass by Spoofing Vulnerability
Overview:

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 the password plugin of the Roundcube Webmail was subject to username spoofing via session data which could lead to account takeover.