Cross-site scripting in Roundcube Webmail - CVE-2026-48849
Published: May 25, 2026 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to inject arbitrary script or style content.
The vulnerability exists due to stored cross-site scripting in the subject field of the draft restore dialog when rendering restored draft data. A remote user can save a specially crafted draft subject to inject arbitrary script or style content.
Affected software
Debian Linux
roundcube (Debian package)
How to mitigate CVE-2026-48849
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1