Cross-Site Scripting Vulnerability in Roundcube Webmail Affects Latest Versions
CVE-2026-74998
7.2HIGH
What is CVE-2026-74998?
In versions of Roundcube Webmail preceding 1.6.18 and those in the 1.7.x branch before 1.7.3, a significant security issue exists where responses from the CSS proxy lack proper validation. This oversight can lead to potential information disclosure or exploitation through cross-site scripting (XSS) attacks via MIME sniffing techniques. To mitigate these risks, users are strongly advised to upgrade to the latest versions as soon as possible.
Affected Version(s)
Webmail 1.6.0 < 1.6.18
Webmail 1.7.0 < 1.7.3
