Improper Encoding or Escaping of Output in Roundcube Webmail - #VU124141

 

Improper Encoding or Escaping of Output in Roundcube Webmail - #VU124141

Published: March 19, 2026 / Updated: March 19, 2026


Vulnerability identifier: #VU124141
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Roundcube
Affected software:
Roundcube Webmail

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass fixed position CSS mitigation by using !important declarations.

The vulnerability exists due to improper output neutralization in CSS filtering mechanism when processing HTML email content. A remote attacker can send a specially crafted email containing styles with "!important" declarations to override fixed position restrictions.

This can be exploited to manipulate email display and potentially enable phishing or UI spoofing attacks.


Remediation

Install security update from vendor's website.

Sources