Server-Side Request Forgery (SSRF) in Roundcube Webmail - CVE-2026-48845

 

Server-Side Request Forgery (SSRF) in Roundcube Webmail - CVE-2026-48845

Published: May 25, 2026 / Updated: September 25, 2026


Vulnerability identifier: #VU132216
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48845
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to make the application fetch local or private URLs despite restrictions.

The vulnerability exists due to improper access control in remote resource fetching when handling local or private URLs while remote resources are disallowed. A remote attacker can supply a specially crafted URL to make the application fetch local or private URLs despite restrictions.

The issue occurs when remote resources are not allowed.


Affected software

Roundcube Webmail
Debian Linux
roundcube (Debian package)

How to mitigate CVE-2026-48845

Install security update from vendor's website.

Roundcube Webmail - addressed in versions 1.6.16, 1.7.1
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1

External References

Related Security Bulletins