Improper HTML/CSS Sanitization in Roundcube Webmail
CVE-2026-75000

5.8MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-75000?

Inversions of Roundcube Webmail prior to version 1.6.18 and in the 1.7.x series before version 1.7.3 are susceptible to a vulnerability involving improper sanitization of the SVG animate 'by' attribute. This flaw allows unauthorized bypass of remote image blocking mechanisms. Consequently, it may lead to potential information disclosure or escalated privileges for malicious users. It is crucial for users to upgrade to the recommended versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Webmail 1.6.0 < 1.6.18

Webmail 1.7.0 < 1.7.3

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.