#VU124136 Deserialization of Untrusted Data in Roundcube Webmail
Published: March 19, 2026
Roundcube Webmail
Roundcube
Description
The vulnerability allows a remote attacker to execute arbitrary code or write arbitrary files.
The vulnerability exists due to unsafe deserialization in redis/memcache session handler when processing session data. A remote attacker can send a specially crafted session payload to execute arbitrary code or write arbitrary files.
No authentication is required to exploit this vulnerability.