GHSA-46pv-mj2g-93gh

Suggest an improvement
Source
https://github.com/advisories/GHSA-46pv-mj2g-93gh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-46pv-mj2g-93gh/GHSA-46pv-mj2g-93gh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-46pv-mj2g-93gh
Aliases
Published
2026-04-03T06:31:32Z
Modified
2026-04-04T07:11:22Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Roundcube Webmail: Incorrect password comparison in the password plugin
Details

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.

Database specific
{
    "cwe_ids": [
        "CWE-843"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-04T06:54:24Z",
    "nvd_published_at": "2026-04-03T05:16:22Z",
    "severity": "MODERATE"
}
References

Affected packages

Packagist / roundcube/roundcubemail

Package

Name
roundcube/roundcubemail
Purl
pkg:composer/roundcube/roundcubemail

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.7-beta
Fixed
1.7-rc5

Affected versions

1.*
1.7-beta
1.7-beta2
1.7-rc
1.7-rc2
1.7-rc3
1.7-rc4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-46pv-mj2g-93gh/GHSA-46pv-mj2g-93gh.json"