Information Disclosure Vulnerability in Roundcube Webmail by Roundcube
CVE-2026-48846
6.5MEDIUM
What is CVE-2026-48846?
In certain versions of Roundcube Webmail, a vulnerability exists that allows an attacker to bypass the remote image blocking feature by utilizing a specially crafted CSS var() value within an email. This security flaw can lead to unauthorized access to sensitive information, as it compromises the intended protective measures designed to shield users from potential threats embedded in remote images.
Affected Version(s)
Webmail 1.6.0 < 1.6.16
Webmail 1.7.0 < 1.7.1
