Input validation error in Roundcube Webmail - CVE-2026-48846
Published: May 25, 2026 / Updated: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause remote images to be loaded despite blocking restrictions.
The vulnerability exists due to improper input validation in remote image blocking logic when processing CSS var() constructs. A remote attacker can supply specially crafted content using CSS var() to cause remote images to be loaded despite blocking restrictions.
Affected software
Debian Linux
roundcube (Debian package)
How to mitigate CVE-2026-48846
roundcube (Debian package) - addressed in versions 1.6.5+dfsg-1+deb12u9, 1.6.16+dfsg-0+deb13u1