Protection mechanism failure in Roundcube Webmail - CVE-2026-25916
Published: February 8, 2026 / Updated: February 13, 2026
Vulnerability identifier: #VU122451
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-25916
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures. A remote attacker can send a specially crafted email and bypass image blocking via SVG content.
Affected software
Roundcube Webmail
Debian Linux
Fedora
Ubuntu
roundcube (Ubuntu package)
roundcubemail
roundcube (Debian package)
Debian Linux
Fedora
Ubuntu
roundcube (Ubuntu package)
roundcubemail
roundcube (Debian package)
How to mitigate CVE-2026-25916
Install updates from vendor's website.
Roundcube Webmail - addressed in versions 1.5.13, 1.6.13
roundcube (Ubuntu package) - addressed in versions 1.2~beta+dfsg.1-0ubuntu1+esm8, 1.3.6+dfsg.1-1ubuntu0.1~esm8, 1.4.3+dfsg.1-1ubuntu0.1~esm8, 1.5.0+dfsg.1-2ubuntu0.1~esm6, 1.6.6+dfsg-2ubuntu0.1+esm3
roundcubemail - addressed in versions 1.5.13-1.el9, 1.6.13-1.el10_1, 1.6.13-1.el10_2, 1.6.13-1.fc42, 1.6.13-1.fc43
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u7, 1.6.13+dfsg-0+deb13u1
roundcube (Ubuntu package) - addressed in versions 1.2~beta+dfsg.1-0ubuntu1+esm8, 1.3.6+dfsg.1-1ubuntu0.1~esm8, 1.4.3+dfsg.1-1ubuntu0.1~esm8, 1.5.0+dfsg.1-2ubuntu0.1~esm6, 1.6.6+dfsg-2ubuntu0.1+esm3
roundcubemail - addressed in versions 1.5.13-1.el9, 1.6.13-1.el10_1, 1.6.13-1.el10_2, 1.6.13-1.fc42, 1.6.13-1.fc43
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u7, 1.6.13+dfsg-0+deb13u1