Input validation error in Roundcube Webmail - CVE-2026-48846

 

Input validation error in Roundcube Webmail - CVE-2026-48846

Published: May 25, 2026 / Updated: September 25, 2026


Vulnerability identifier: #VU132217
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48846
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause remote images to be loaded despite blocking restrictions.

The vulnerability exists due to improper input validation in remote image blocking logic when processing CSS var() constructs. A remote attacker can supply specially crafted content using CSS var() to cause remote images to be loaded despite blocking restrictions.


Affected software

Roundcube Webmail
Debian Linux
roundcube (Debian package)

How to mitigate CVE-2026-48846

Install security update from vendor's website.

Roundcube Webmail - addressed in versions 1.6.16, 1.7.1
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1

External References

Related Security Bulletins