SVG Image Handling Vulnerability in Roundcube Webmail
CVE-2026-75003

5.8MEDIUM

Key Information:

Vendor

Roundcube

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-75003?

An issue in Roundcube Webmail versions prior to 1.6.18 and in the 1.7.x series before 1.7.3 allows an unclosed url() in a FuncIRI attribute of an SVG image. This oversight can bypass the protection mechanisms for remote image loading, which may lead to unauthorized information disclosure or privilege escalation within the application. It is important for users and administrators to update their installations to the latest versions to mitigate potential risks.

Affected Version(s)

Webmail 1.6.0 < 1.6.18

Webmail 1.7.0 < 1.7.3

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.