Code Injection in Roundcube Webmail - #VU132219

 

Code Injection in Roundcube Webmail - #VU132219

Published: May 25, 2026


Vulnerability identifier: #VU132219
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Roundcube
Affected software:
Roundcube Webmail

Detailed vulnerability description

The vulnerability allows a remote user to inject and execute arbitrary code.

The vulnerability exists due to code injection in the LDAP autovalues option when evaluating configured values. A remote user can supply crafted values in LDAP autovalues configuration to inject and execute arbitrary code.

Exploitation requires use of the LDAP autovalues option.


Remediation

Install security update from vendor's website.

Sources