#VU124141 Improper Encoding or Escaping of Output in Roundcube Webmail
Published: March 19, 2026 / Updated: March 19, 2026
Roundcube Webmail
Roundcube
Description
The vulnerability allows a remote attacker to bypass fixed position CSS mitigation by using !important declarations.
The vulnerability exists due to improper output neutralization in CSS filtering mechanism when processing HTML email content. A remote attacker can send a specially crafted email containing styles with "!important" declarations to override fixed position restrictions.
This can be exploited to manipulate email display and potentially enable phishing or UI spoofing attacks.