Code Injection in Roundcube Webmail - #VU132219
Published: May 25, 2026
Roundcube Webmail
Detailed vulnerability description
The vulnerability allows a remote user to inject and execute arbitrary code.
The vulnerability exists due to code injection in the LDAP autovalues option when evaluating configured values. A remote user can supply crafted values in LDAP autovalues configuration to inject and execute arbitrary code.
Exploitation requires use of the LDAP autovalues option.