Improper HTML/CSS Sanitization in Roundcube Webmail
CVE-2026-75000
5.8MEDIUM
What is CVE-2026-75000?
Inversions of Roundcube Webmail prior to version 1.6.18 and in the 1.7.x series before version 1.7.3 are susceptible to a vulnerability involving improper sanitization of the SVG animate 'by' attribute. This flaw allows unauthorized bypass of remote image blocking mechanisms. Consequently, it may lead to potential information disclosure or escalated privileges for malicious users. It is crucial for users to upgrade to the recommended versions to mitigate the risks associated with this vulnerability.
Affected Version(s)
Webmail 1.6.0 < 1.6.18
Webmail 1.7.0 < 1.7.3
