CVE-2018-1000071: Roundcube Webmail

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

Affected products

Published 2018-03-13. Last modified 2026-06-17.